DATA PROCESSING AGREEMENT (DPA) Custard People Ltd

This DPA forms part of your agreement with Custard Ltd and applies where Custard processes personal data on behalf of the Controller in connection with the Service.

Last updated: 23rd March 2026

1. Definitions

  • Controller: the customer organisation using Custard
  • Processor: Custard People Ltd
  • Personal Data: any information relating to an identified or identifiable natural person, as defined under UK GDPR
  • UK GDPR: the UK General Data Protection Regulation as retained in UK law
  • Sub-processor: any third party engaged by Custard to process Personal Data on its behalf

 

2. Scope

This DPA applies to all Personal Data processed by Custard on behalf of the Controller in connection with the provision of the Service, as described in the Terms of Service.

 

3. Processing Instructions

Custard will:

  • process Personal Data only on documented instructions from the Controller
  • only use Personal Data to provide the Service
  • not use Personal Data for unrelated purposes without the Controller’s prior written consent
  • inform the Controller promptly if, in Custard’s opinion, any instruction infringes applicable data protection law

 

4. Nature & Purpose of Processing

Processing activities include:

  • collecting feedback responses from team members
  • storing and organising user and feedback data
  • analysing responses to generate insights
  • delivering recommendations to managers via the platform

Purpose: To provide the Custard platform and associated features as described in the Terms of Service.

 

5. Categories of Personal Data

  • employee identifiers (name, email address, job role)
  • feedback responses submitted through the platform
  • usage and activity data (logins, interactions)
  • manager-employee relationship data (team structure)

 

6. Categories of Data Subjects

  • employees and team members
  • managers and platform administrators
  • other users of the platform

 

7. Duration of Processing

Custard will process Personal Data for the duration of the Service agreement, plus any period required to fulfil legal obligations or respond to deletion requests following termination.

 

8. Processor Obligations

Custard agrees to:

  • ensure that personnel authorised to process Personal Data are bound by appropriate confidentiality obligations
  • implement appropriate technical and organisational security measures (see Section 11)
  • assist the Controller in meeting its GDPR obligations, including responding to data subject rights requests
  • not engage new Sub-processors without prior notification to the Controller (see Section 9)
  • make available to the Controller all information reasonably necessary to demonstrate compliance with this DPA
  • upon reasonable notice, support audits or inspections conducted by the Controller or an appointed third party, or provide responses to security questionnaires in lieu of a full audit

 

9. Sub-processors

Custard currently uses the following Sub-processors:

 

ProviderPurpose
Laravel CloudCloud hosting and infrastructure
StripePayment processing
ResendTransactional email delivery
GoHighLevelMarketing and communications
ClaudeAI-powered insights & chat
SupabaseResource embedding database
AnthropicImport team members validation

Custard will:

  • provide the Controller with at least 14 days’ prior written notice before engaging a new Sub-processor
  • ensure all Sub-processors are bound by data protection obligations no less protective than those in this DPA
  • remain fully responsible for the acts and omissions of Sub-processors

The Controller may object to the use of a new Sub-processor within the notice period by notifying Custard in writing. If the parties cannot resolve the objection, either party may terminate the relevant Service on written notice.

 

10. Data Subject Rights

Custard will assist the Controller in responding to requests from data subjects exercising their rights under UK GDPR, including rights of:

  • access
  • rectification
  • erasure
  • restriction of processing
  • data portability
  • objection to processing

Custard will notify the Controller of any data subject request received directly, without undue delay, and will not respond to such requests without the Controller’s authorisation unless required by law.

 

11. Security Measures

Custard implements appropriate technical and organisational measures to protect Personal Data against unauthorised access, loss, or destruction, including:

  • role-based access controls
  • encryption of data in transit and at rest where appropriate
  • secure cloud hosting via AWS
  • regular monitoring and security assessments
  • staff training on data protection obligations

 

12. Data Breach Notification

In the event of a Personal Data breach, Custard will:

  • notify the Controller within 72 hours of becoming aware of the breach
  • provide sufficient detail to allow the Controller to meet its own notification obligations to the ICO
  • include in the notification: the nature of the breach, categories and approximate number of data subjects affected, likely consequences, and measures taken or proposed to address the breach
  • cooperate with the Controller in investigating and remediating the breach

 

13. Data Retention & Deletion

Upon termination of the Service:

  • Custard will manually delete or return all Personal Data within 90 days of the termination date
  • Custard will provide written confirmation of deletion upon request
  • Custard may retain Personal Data beyond this period only where required by applicable law, and will inform the Controller of any such retention

 

14. International Transfers

Where Personal Data is transferred outside the UK or EEA, Custard will ensure appropriate safeguards are in place, including:

  • use of the UK International Data Transfer Agreement (IDTA) or Standard Contractual Clauses (SCCs) as applicable
  • transfer impact assessments where required
  • ensuring receiving parties provide an equivalent level of protection

 

15. Liability

Each party is responsible for its own obligations under applicable data protection law. Custard’s liability under this DPA is subject to the limitations set out in the Terms of Service, except where liability cannot be limited by law.

 

16. Governing Law

This DPA is governed by the laws of England and Wales.

 

17. Contact

Data protection queries: hello@itscustard.com