All documents

Takes effect 1 October 2026 · version 0.1-draft

Data Processing Agreement

Version history (1)

DRAFT — NOT LEGALLY REVIEWED. This document was drafted from the Interu Usage Conditions, Service Level Agreement and Privacy Policy. It has not been reviewed by a qualified lawyer, and iov42 has not adopted it. Passages in square brackets are open questions. Do not send this to a customer and do not publish it until it has been through legal review and the open items are resolved.

This Data Processing Agreement (DPA) forms part of the agreement between iov42 and the Customer for the supply of Interu (the Principal Agreement). It records the terms on which iov42 processes personal data on the Customer's behalf.

Where this DPA conflicts with the Principal Agreement, this DPA prevails in respect of the processing of personal data. In all other respects the Principal Agreement continues unchanged.

1. Definitions #

Applicable Data Protection Law means, as applicable to a party's processing: (a) Regulation (EU) 2016/679 (EU GDPR); (b) the EU GDPR as it forms part of the law of England and Wales, Scotland and Northern Ireland by virtue of section 3 of the European Union (Withdrawal) Act 2018 (UK GDPR); (c) the Data Protection Act 2018; and (d) the Privacy and Electronic Communications Regulations 2003, in each case as amended or replaced from time to time.

Controller, processor, data subject, personal data, personal data breach, processing and supervisory authority have the meanings given to them in the UK GDPR.

Customer means the entity identified as the licensee in the Principal Agreement.

Customer Personal Data means personal data contained within Customer Data that iov42 processes on the Customer's behalf under the Principal Agreement.

Customer Data means data the Customer or its Users upload to, or generate through, Interu.

iov42 means iov42 IP Limited, a company registered in England and Wales with company number [COMPANY NUMBER], whose registered office is at [REGISTERED OFFICE].

Interu means the Interu supply chain data compliance platform and related services supplied under the Principal Agreement.

Restricted Transfer means a transfer of personal data to a country outside the United Kingdom or the European Economic Area which is not the subject of an adequacy decision.

Standard Contractual Clauses means (a) for transfers subject to the EU GDPR, the clauses annexed to Commission Implementing Decision (EU) 2021/914; and (b) for transfers subject to the UK GDPR, the International Data Transfer Addendum issued by the Information Commissioner under section 119A of the Data Protection Act 2018.

Subprocessor means any processor engaged by iov42 to process Customer Personal Data.

User has the meaning given to it in the Principal Agreement.

2. Roles of the parties #

2.1 Customer Personal Data #

In respect of Customer Personal Data, the Customer is the controller and iov42 is the processor. Clauses 3 to 12 of this DPA govern that processing.

The Customer determines the purposes and means of processing Customer Personal Data and is responsible for the accuracy, quality and lawfulness of that data and of the instructions it gives iov42.

2.2 Data for which iov42 is a controller #

iov42 is an independent controller in respect of:

  • account and login data for Users, including first name, last name, email address and credentials;
  • data about individuals at the Customer who contact iov42, including in connection with support; and
  • service usage and technical data that iov42 processes to operate, secure, support and improve Interu.

iov42 processes that data in accordance with its Privacy Policy. The parties may each be an independent controller of the same personal data, in which case neither is a joint controller with the other, and this DPA does not apply to that processing.

2.3 Change of role #

If the correct characterisation of a party's role changes, whether because of a change in law, regulatory guidance or the way Interu is used, the parties will work together in good faith to agree the changes to this DPA that are necessary as a result.

3. Scope of processing #

iov42 will process Customer Personal Data only:

  • for the subject matter, duration, nature and purposes set out in Annex 1;
  • in respect of the types of personal data and categories of data subject set out in Annex 1; and
  • on the Customer's documented instructions, which comprise this DPA, the Principal Agreement, and any further written instruction the Customer gives through the support channels set out in the Service Level Agreement.

iov42 will not sell Customer Personal Data, and will not use it to train machine learning models other than to provide Interu to the Customer.

3.1 Processing required by law #

If Applicable Data Protection Law requires iov42 to process Customer Personal Data otherwise than on the Customer's instructions, iov42 will inform the Customer of that requirement before processing, unless the law prohibits it from doing so on important grounds of public interest.

3.2 Unlawful instructions #

iov42 will inform the Customer without undue delay if, in its opinion, an instruction infringes Applicable Data Protection Law. iov42 is not obliged to give legal advice, and may suspend the affected processing until the instruction is withdrawn, confirmed or amended.

4. Confidentiality #

iov42 will ensure that any person authorised to process Customer Personal Data is subject to a duty of confidentiality, whether contractual or statutory, that survives the end of their engagement. iov42 will limit access to Customer Personal Data to those personnel who need it to perform iov42's obligations under the Principal Agreement.

5. Security #

iov42 will implement and maintain appropriate technical and organisational measures to protect Customer Personal Data against accidental or unlawful destruction, loss, alteration, unauthorised disclosure and unauthorised access, taking into account the state of the art, the costs of implementation, the nature, scope, context and purposes of processing, and the risks to data subjects.

The measures in place at the date of this DPA are described in Annex 2. iov42 may update them, provided the level of protection is not reduced.

6. Subprocessors #

The Customer gives iov42 general authorisation to engage Subprocessors. The Subprocessors engaged at the date of this DPA are published at legal.interu.io/subprocessors, which forms Annex 3.

iov42 will give the Customer at least [30] days' notice before a new Subprocessor begins processing Customer Personal Data. Notice will be given [by email to the Customer's nominated contact / by updating the published list — CONFIRM WHICH]. The Customer may object on reasonable grounds relating to data protection within that period, and the parties will discuss the objection in good faith. If it cannot be resolved, the Customer may terminate the affected part of the Principal Agreement without penalty on written notice.

iov42 will impose on each Subprocessor data protection obligations no less protective than those in this DPA, and remains fully liable to the Customer for each Subprocessor's performance.

7. International transfers #

iov42 hosts Customer Data in data centres located within the European Union.

iov42 will not make a Restricted Transfer of Customer Personal Data, or permit a Subprocessor to do so, unless the transfer is:

  • covered by an adequacy decision applicable to the transfer;
  • subject to the Standard Contractual Clauses or another safeguard under Article 46 of the EU GDPR or UK GDPR; or
  • otherwise permitted under Article 49.

Where the Standard Contractual Clauses apply, they are incorporated into this DPA, the Customer is the data exporter, and Annex 1 and Annex 2 populate their annexes. iov42 will provide details of the mechanism relied on for any transfer on request.

8. Assistance to the Customer #

8.1 Data subject rights #

Taking into account the nature of the processing, iov42 will assist the Customer by appropriate technical and organisational measures, insofar as possible, to respond to requests from data subjects exercising their rights under Applicable Data Protection Law.

If iov42 receives such a request directly from a data subject in respect of Customer Personal Data, it will not respond to it other than to acknowledge receipt and direct the data subject to the Customer, and will inform the Customer without undue delay.

8.2 Impact assessments and consultation #

iov42 will provide reasonable assistance to the Customer with data protection impact assessments and prior consultation with a supervisory authority under Articles 35 and 36, taking into account the nature of the processing and the information available to iov42.

9. Personal data breach #

iov42 will notify the Customer without undue delay, and in any event within [48] hours, after becoming aware of a personal data breach affecting Customer Personal Data.

The notification will describe, to the extent known at the time:

  • the nature of the breach, including where possible the categories and approximate number of data subjects and records concerned;
  • the likely consequences of the breach;
  • the measures taken or proposed to address it and mitigate its effects; and
  • a contact point for further information.

Where iov42 cannot provide all of that information at once, it may provide it in phases without undue further delay. iov42 will cooperate with the Customer and take the reasonable steps the Customer directs to assist in investigating and remedying the breach.

Notification of a breach is not an acknowledgement of fault or liability.

10. Deletion and return #

On termination or expiry of the Principal Agreement, iov42 will, at the Customer's election, delete or return Customer Personal Data, and delete existing copies, unless Applicable Data Protection Law requires it to retain them.

The Customer must make that election within [30] days of termination or expiry. If it does not, iov42 may delete the Customer Personal Data.

Customer Personal Data held in backups will be deleted in accordance with iov42's backup retention cycle, described in the Service Level Agreement. Until deletion, iov42 will continue to protect that data in accordance with this DPA and will not process it for any other purpose.

11. Audit #

iov42 will make available to the Customer the information reasonably necessary to demonstrate compliance with this DPA and Article 28 of the UK GDPR.

iov42 will allow for and contribute to audits, including inspections, conducted by the Customer or an auditor it mandates, subject to the following:

  • the Customer gives at least [30] days' written notice;
  • audits take place during business hours and no more than once in any twelve month period, unless required by a supervisory authority or following a personal data breach affecting Customer Personal Data;
  • the auditor is not a competitor of iov42 and is bound by confidentiality obligations;
  • the audit does not require iov42 to disclose the data or breach the confidentiality of any other customer, nor to give access to any part of its systems whose disclosure would compromise its security; and
  • the Customer bears its own costs and iov42's reasonable costs of supporting the audit.

iov42 may satisfy an audit request by providing [a current third-party audit report or certification — CONFIRM WHICH, IF ANY, IOV42 HOLDS] where that reasonably addresses the scope of the request.

12. Liability #

Each party's liability under this DPA is subject to the exclusions and limitations of liability in the Principal Agreement.

Nothing in this DPA limits either party's liability to a data subject or a supervisory authority under Applicable Data Protection Law.

13. Term #

This DPA takes effect on the date the Principal Agreement takes effect and continues for as long as iov42 processes Customer Personal Data. Clauses that by their nature should survive termination will do so.

14. Governing law #

This DPA is governed by the laws of England and Wales, and the parties submit to the exclusive jurisdiction of the courts of England and Wales, in each case as provided in the Principal Agreement. Where the Standard Contractual Clauses apply, the governing law and forum provisions of those clauses prevail in respect of the transfers they govern.

15. Contact #

Data protection enquiries relating to this DPA should be sent to privacy@iov42.com.

Annex 1. Details of the processing #

Subject matter. iov42's provision of Interu to the Customer under the Principal Agreement.

Duration. The term of the Principal Agreement, plus the period until Customer Personal Data is deleted or returned under clause 10.

Nature and purpose of the processing. Hosting, storage, organisation, retrieval, transmission and deletion of Customer Data so the Customer can record, share and audit supply chain data, prepare and support regulatory submissions, and demonstrate compliance obligations, including under Regulation (EU) 2023/1115 on deforestation-free products.

Types of personal data. Personal data contained in Customer Data, which the Customer determines. Typically:

  • names, job titles, email addresses and telephone numbers of individuals at the Customer's suppliers, producers and other counterparties;
  • names and identifiers of individual producers, smallholders and landowners appearing in supply chain records;
  • geolocation data for plots of land, where that data relates to an identifiable individual;
  • identifiers appearing in due diligence documents, certificates, purchase orders and shipping records the Customer uploads.

Categories of data subject.

  • personnel of the Customer's suppliers and counterparties;
  • individual producers, smallholders and landowners in the Customer's supply chain;
  • any other individual identified in Customer Data.

Sensitive data. Interu is not designed for special category data under Article 9 or data relating to criminal convictions under Article 10, and the Customer must not upload such data without iov42's prior written agreement and the additional safeguards agreed with it.

Frequency. Continuous for the duration of the Principal Agreement.

Annex 2. Technical and organisational measures #

[TO BE VERIFIED AGAINST CURRENT PRACTICE BEFORE PUBLICATION. The following is drawn from the Service Level Agreement and Privacy Policy and must be confirmed with the engineering team.]

Hosting and residency. Customer Data is stored in data centres within the European Union and is subject to EU data protection law.

Segregation. Interu stores customer data in a central database in which each tenant has a segregated storage space.

Access control. Access to Customer Personal Data is limited to personnel with a business need. Access is authenticated and subject to the confidentiality obligations in clause 4.

Encryption. [Encryption in transit and at rest — CONFIRM SPECIFICS.]

Resilience and backup. Document data is backed up continuously, generally within a minute of storage. Database data is backed up periodically. iov42 retains at least 30 days of both. Backups are held in storage separate from the database server and replicated across multiple geographic regions.

Restoration. Backups are restored only in the event of a major platform issue, at iov42's discretion, as described in the Service Level Agreement. Individual database records cannot be restored in isolation.

Security testing and monitoring. iov42 operates automated security testing, intrusion detection and other measures designed to protect against and mitigate security incidents.

Incident response. iov42 maintains procedures for handling suspected personal data breaches, including notification under clause 9 and, for P0 incidents, a full incident report to users within three business days as provided in the Service Level Agreement.

Certifications. [State any certification held, e.g. ISO/IEC 27001, SOC 2 — or remove this heading.]

Annex 3. Subprocessors #

The current list of Subprocessors is published at legal.interu.io/subprocessors and is incorporated into this DPA by reference.