← Back to BuyerPro

Data Processing Agreement

1. Parties and scope

This Data Processing Agreement ("DPA") is between the BuyerPro customer identified in the account ("Customer", "you") and [COMPANY LEGAL NAME] of [REGISTERED ADDRESS] ("BuyerPro", "we").

It forms part of the Terms of Service and applies whenever we process personal data on your behalf. Where it conflicts with the Terms of Service on a data protection matter, this DPA wins.

"Data Protection Law" means the UK GDPR, the Data Protection Act 2018, the EU GDPR (Regulation 2016/679), and any other law about personal data that applies to either of us. Terms such as controller, processor, personal data, processing, data subject and personal data breach have the meanings given in that law.

2. Roles

For the correspondence and content you send to BuyerPro, you are the controller and we are the processor. You decide what is sent to us and why. We process it only to provide the service.

We are an independent controller for our own limited purposes: your account and billing records, service and security logs, and communications with you about the service. Our Privacy Policy covers that.

3. Processing on instructions

We will process personal data only on your documented instructions. Your use of the service, together with the Terms of Service and this DPA, constitutes those instructions. Additional instructions must be agreed in writing, and we may charge for anything outside the ordinary operation of the service.

We will tell you if, in our opinion, an instruction breaches Data Protection Law. We may decline to act on it while we resolve the point with you.

We will not process the data for our own purposes, will not sell it, and will not use it to train AI models — ours or anyone else's.

Your obligations. You confirm that you have a lawful basis for sending us the correspondence, that you have given the people in it the information Data Protection Law requires — including that a processor analyses it — and that you have not sent us special category data, criminal offence data, or payment card numbers. On request we will give you wording you can use in your own privacy notice or email footer.

4. Confidentiality

We keep personal data confidential. Everyone we authorise to access it is bound by a written duty of confidentiality that survives the end of their engagement, and access is limited to those who need it to run and support the service.

5. Security

We implement appropriate technical and organisational measures under Article 32, described in Annex 2. We may change them as technology moves, but not in a way that materially reduces protection.

6. Sub-processors

You give us general authorisation to appoint sub-processors. The current list is published at buyerpro.ai/subprocessors.

Before we add or replace one, we will give you 30 days' notice by email and by updating that page. If you have a reasonable data protection objection, tell us within those 30 days and we will work with you to find a solution. If we cannot, you may terminate the affected part of the service without penalty and receive a pro-rata refund of any prepaid fees.

We impose data protection obligations on every sub-processor that are no less protective than those in this DPA, and we remain fully liable to you for their performance.

7. Helping you answer individuals

If someone contacts us directly to exercise their rights over data in your account, we will not respond substantively. We will tell them to contact you, and tell you within 5 working days.

Taking account of the nature of the processing, we will help you meet your obligations under Articles 12 to 23 — including access, correction, erasure, restriction, portability and objection. The service gives you direct access to your threads; where a request needs work beyond that, we will assist and will not charge for reasonable assistance.

A limitation we want you to know about. We encrypt each conversation under its own key, which is good for security but means we cannot search across message bodies in bulk. If someone asks to be erased, we can find and delete every message they sent or received. We cannot automatically find places where a third party named them inside a message body. In those cases we identify the affected threads and review them manually with you.

We will also give you reasonable help with data protection impact assessments and prior consultation under Articles 35 and 36.

8. Personal data breaches

We will notify you without undue delay and in any event within 24 hours of becoming aware of a personal data breach affecting your data — so that you can meet your own 72-hour deadline.

Our notice will describe the nature of the breach, the categories and approximate number of data subjects and records affected, the likely consequences, the measures we have taken or propose, and a contact point. Where we do not have all of it at once, we will send what we have and follow up.

We will not notify a regulator or any data subject on your behalf unless you ask us to, since that is your decision as controller.

9. International transfers

Our infrastructure and sub-processors are located in the United States. By using the service you instruct us to transfer personal data there.

Where personal data originating in the UK or the EEA is transferred, we rely on the European Commission's Standard Contractual Clauses (Decision 2021/914), module three (processor to processor) where applicable, and the UK Information Commissioner's International Data Transfer Addendum. Those clauses are incorporated into this DPA by reference and take precedence over it in the event of conflict.

The supplementary measures we apply are set out in Annex 2 — in particular that message content is encrypted with keys we control and is never stored in plain text.

10. Deletion and return

During your subscription you can export your data at any time — ask us and we will provide it in a structured, machine-readable format.

When the agreement ends, we will delete all personal data we process on your behalf within 30 days, unless the law requires us to keep it. Ask before that window closes if you want a final export.

Deletion means permanent deletion from our live systems. Backups roll off on their own cycle within 35 days and are never restored selectively. We will confirm deletion in writing on request.

Separately, we run a nightly retention job that deletes content 24 months after the last message in a thread. The full schedule is published in section 9 of the Privacy Policy.

11. Audit

We will make available the information needed to demonstrate compliance with Article 28. In the first instance we will answer a written security questionnaire and provide our current documentation.

If that is not enough, you may audit us — or appoint an independent auditor who is not a competitor of ours and who signs a confidentiality agreement — no more than once a year, on 30 days' notice, during business hours, without unreasonable disruption. You bear the cost unless the audit finds a material breach of this DPA. You may audit more often if a regulator requires it or following a personal data breach affecting your data.

12. Liability and general

The limitations of liability in the Terms of Service apply to this DPA, except where Data Protection Law does not allow them to.

This DPA is governed by the laws of [JURISDICTION], except that the Standard Contractual Clauses are governed as they themselves specify. If a provision is unenforceable, the rest stands.

Annex 1 — Details of processing

Subject matterAnalysis of supplier correspondence to produce procurement coaching.
DurationThe term of the subscription, plus the retention and deletion periods above.
Nature and purposeReceiving, storing (encrypted), analysing and summarising email threads; extracting commitments and dates; assigning risk levels; generating coaching emails and draft replies; sending those to the Customer.
Types of personal dataNames and business email addresses of the Customer's staff and their supplier contacts; the content of email messages and attachments; message metadata such as subjects, timestamps and headers; commitments, dates and risk assessments derived from that content.
Special category dataNone. The service is not designed for it and the Customer must not send it.
Categories of data subjectThe Customer's employees and contractors; employees and contractors of the Customer's suppliers and other counterparties who appear in the correspondence.
FrequencyContinuous, whenever the Customer copies correspondence to the service.

Annex 2 — Security measures

The measures we currently apply under Article 32:

AreaMeasure
Encryption at restEvery message body, attachment and extracted signal is encrypted with AES-256-GCM before storage. Nothing is stored in plain text; if encryption fails the data is discarded rather than written.
Key managementA separate key is derived for each conversation using HKDF-SHA256. Derived keys are never stored. The master key is held only in the application environment, never in the database, and is not accessible to sub-processors.
Encryption in transitTLS on all connections. Inbound mail is signed with HMAC-SHA256 and timestamped between our mail router and our application, so forged or replayed messages are rejected.
Access controlAdministrative access requires a separate secret presented in an authorisation header, never in a URL. Customer-facing links are scoped to a single thread or account and expire.
Tenant isolationEvery record is scoped to a tenant, queries are filtered by tenant, and isolation is covered by an automated test suite.
Input safetyAll inbound content is treated as untrusted. We apply documented defences against prompt injection — attempts to hide instructions inside an email to manipulate the AI.
Application securityParameterised database queries throughout. Strict Content Security Policy, HSTS, and frame and content-type protections on all web responses. No third-party scripts, trackers or cookies on our website.
Logging and auditAn audit log records actions taken on accounts. Logs hold identifiers and timestamps, never message content.
MinimisationA nightly job permanently deletes data past its retention period. IP addresses collected for abuse prevention are erased after 30 days.
ResilienceManaged database with automated backups and point-in-time recovery, health checks, and alerting to an on-call channel.
Sub-processor controlEach sub-processor is under a written data protection agreement no less protective than this DPA. The list is published and change notice is given.