Decised

Legal

Data processing agreement

Last updated 1 September 2026.

This Data Processing Agreement (“DPA”) forms part of the Commercial Agreement (or other written agreement) between Decised and the Customer when Decised processes personal data on the Customer’s documented instructions in connection with Workspaces (Beta) or other organisational use of the Service.

This DPA does not create joint controllership. Decised may process Service Data (security logs, authentication records, aggregated usage) as an independent controller for security, abuse prevention and operating the Service, as described in the Privacy Policy.

1. Roles

  • Customer is the controller (or a processor acting for a controller) of Customer Personal Data.
  • Decised is the processor of Customer Personal Data processed to provide the Service on Customer’s instructions.

2. Subject matter and duration

Decised processes Customer Personal Data for the duration of the Customer’s use of the Service, including account identifiers of invited members, workspace membership, shared cases, evidence and uploads associated with the Customer’s organisation, and related support communications. Processing ends when the data is deleted or returned under Section 8, except for limited retention required by law or anonymised security records.

3. Customer instructions and obligations

Customer instructs Decised to process Customer Personal Data only to provide, secure and support the Service; comply with law; and follow documented configuration choices Customer makes in the product (for example invitations and roles). Customer warrants it has a lawful basis and any required notices or consents for such processing, and will not instruct Decised to process special-category data without a separate written agreement.

4. Decised obligations

Decised shall:

  • Process Customer Personal Data only on documented instructions, unless required by UK law.
  • Ensure persons authorised to process the data are bound by confidentiality.
  • Implement appropriate technical and organisational measures, including access controls, hashed credentials, session security and backup practices appropriate to the Service.
  • Not engage a subprocessor without the safeguards in Section 5 and the published Subprocessors list.
  • Assist Customer, taking into account the nature of processing, with data-subject requests, DPIAs and breach notifications reasonably required under UK GDPR.
  • Make available information reasonably necessary to demonstrate compliance with this DPA.

5. Subprocessors

Customer authorises Decised to use subprocessors listed at /legal/subprocessors. Decised will impose data-protection terms no less protective than this DPA. Decised will update that page when subprocessors change. Customer may object on reasonable data-protection grounds within 10 business days of a material addition; if unresolved, Customer may stop using the affected features.

6. International transfers

Where Decised transfers Customer Personal Data outside the UK, it will ensure a UK adequacy regulation applies or appropriate safeguards are in place (such as the UK International Data Transfer Agreement / Addendum to the EU SCCs) with the relevant recipient.

7. Security incidents

Decised will notify Customer without undue delay after becoming aware of a personal data breach affecting Customer Personal Data, and will provide information reasonably available to help Customer meet its own notification duties.

8. Return and deletion

On termination of organisational use, Customer may export available materials. Decised will delete Customer Personal Data from active systems within a reasonable period consistent with the Data retention notice, unless retention is required by law or needed for dispute resolution in anonymised or minimised form.

9. Liability and order of precedence

Liability under this DPA is subject to the limitations in the Commercial Agreement. If there is a conflict between this DPA and other terms regarding data protection, this DPA prevails.

10. Contact

Privacy / DPA contact: [email protected].