Data Processing Agreement
Last updated: 6 July 2026
The short version
You're the controller
For data about your people, you decide; we process only on your instructions.
Security measures
Row-level isolation, encryption, and access controls (Annex 2).
Named sub-processors
A short, listed set of vendors, with notice before we add one (Annex 3).
Transfers covered
US processing is covered by the UK IDTA, SCCs, or the UK–US Data Bridge (Annex 4).
Deleted on exit
We delete or return your data when the contract ends.
1. Parties and roles
This DPA is between Intelligent Outputs Ltd, a company registered in England and Wales (company number 17288610), trading as Airprose (the "Processor", "we", "us"), and the customer organisation that has accepted our Terms of Service or countersigned the DPA cover sheet (the "Controller", "you").
For the personal data you upload or generate through Airprose about your own staff, referees, clients, and contacts, you are the controller and we are your processor. (Separately, we are an independent controller for the limited account and usage data described in our Privacy Policy — that is not covered by this DPA.)
2. Definitions
Terms like "personal data", "processing", "controller", "processor", "data subject", and "personal data breach" have the meanings given in UK GDPR (the retained EU General Data Protection Regulation as it forms part of UK law) and the Data Protection Act 2018. "Customer Personal Data" means personal data we process on your behalf under the Terms, as described in Annex 1.
3. Scope and instructions
We will process Customer Personal Data only on your documented instructions, including for transfers, unless required to do otherwise by law (in which case we'll tell you first, unless the law prohibits it). Your instructions are: this DPA, the Terms of Service, your configuration and use of the product, and any written instructions you give us.
The subject-matter, duration, nature, purpose, data types, and categories of data subjects are set out in Annex 1.
If we believe an instruction infringes UK GDPR or other data protection law, we will inform you.
4. Our obligations as processor
We will:
- Process Customer Personal Data only as set out in section 3;
- Ensure people authorised to process it are bound by confidentiality;
- Implement appropriate technical and organisational security measures (Annex 2), as required by UK GDPR Article 32;
- Respect the conditions for engaging sub-processors (section 5);
- Assist you, taking into account the nature of processing, to respond to data-subject requests (section 6);
- Assist you with your obligations on security, breach notification, data protection impact assessments, and prior consultation (Articles 32–36), taking into account the information available to us;
- At your choice, delete or return Customer Personal Data at the end of the service (section 8);
- Make available the information necessary to demonstrate compliance with Article 28 and allow for and contribute to audits (section 9).
5. Sub-processors
You give us general authorisation to engage the sub-processors listed in Annex 3 to help deliver the service. Each sub-processor is bound by written terms imposing the same data-protection obligations as this DPA (in particular, appropriate security measures), and we remain liable to you for their performance.
If we add or replace a sub-processor, we will update the list (published at /sub-processors) and give you reasonable prior notice so you can object on reasonable data-protection grounds. If you object and we can't offer a reasonable alternative, you may terminate the affected part of the service.
6. Data-subject requests
If we receive a request from one of your data subjects (for access, erasure, rectification, restriction, portability, or objection), we will not respond directly (unless legally required) and will refer it to you without undue delay. Taking into account the nature of the processing, we will provide reasonable assistance — including through the self-service tools in the product — to help you meet the request within the statutory time limit.
7. Personal data breach
We will notify you without undue delay after becoming aware of a personal data breach affecting Customer Personal Data, and provide the information you reasonably need to meet your own notification obligations to the ICO and affected individuals (which, for a reportable breach, is generally within 72 hours of you becoming aware).
8. International transfers
Some sub-processors process data outside the UK, including in the United States (see Annex 3). Where we transfer Customer Personal Data outside the UK, we ensure an appropriate safeguard is in place, being one or more of: the UK's adequacy regulations / Data Bridge; the UK International Data Transfer Agreement (IDTA) or the UK Addendum to the EU Standard Contractual Clauses (SCCs); or the sub-processor's certification under the UK–US Data Bridge (an extension of the EU–US Data Privacy Framework). The applicable mechanism per sub-processor is summarised in Annex 4.
9. Deletion and return
On termination of the service, and at your choice, we will delete or return all Customer Personal Data and delete existing copies, unless UK law requires us to keep it. Backups are purged on our normal backup cycle (up to 90 days), after which residual copies are irretrievably deleted or anonymised. You can also delete your organisation and all its data yourself at any time from the product.
10. Audit
We will make available to you the information reasonably necessary to demonstrate compliance with UK GDPR Article 28 — normally in the form of our security documentation, the measures in Annex 2, and written responses to your reasonable questions. Where that is insufficient, you (or an independent auditor you appoint, bound by confidentiality) may audit our relevant processing on reasonable prior written notice, no more than once a year unless required by a regulator or following a breach, during business hours and without disrupting our operations.
11. Liability and precedence
This DPA forms part of, and is subject to, the Terms of Service, including the limitation of liability in those Terms, which applies to your and our total aggregate liability under the Terms and this DPA together. If there is a conflict between this DPA and the Terms on the processing of Customer Personal Data, this DPA prevails.
12. Governing law
This DPA is governed by the laws of England and Wales, and the courts of England and Wales have exclusive jurisdiction, matching the Terms of Service.
Annex 1 — Details of the processing
Subject-matter: provision of the Airprose AI-assisted bid/tender-writing service.
Duration: for the term of your account, plus the deletion/return period in section 9.
Nature and purpose: hosting, storing, organising, retrieving, analysing, and generating text from the content you upload, so you can analyse tenders and draft responses; sending service communications; providing team collaboration.
Types of personal data: account data (names, work email addresses, organisation details); and any personal data incidentally contained in the tender documents, library assets, and drafts you upload or create — which may include employee names and roles, referee details, and staff CV/qualification information.
Categories of data subjects: your authorised users; your employees and contractors; your referees and clients; and any individuals named in the documents you upload.
Special-category data: not required by the service. You should avoid uploading special-category data; if your documents contain it, you remain responsible for having a lawful basis and condition for it.
Annex 2 — Security measures
We maintain technical and organisational measures appropriate to the risk, including:
- Tenant isolation: per-organisation data isolation enforced by row-level security policies on every application table.
- Encryption in transit: TLS 1.2+ on all connections.
- Encryption at rest: storage-level encryption for the database and file storage; third-party OAuth tokens additionally encrypted with AES-256-GCM.
- Access control: authentication via a managed identity provider; passwords stored hashed, never in plaintext; least-privilege access; platform-admin access restricted by allowlist and logged in an append-only admin audit log.
- Confidentiality: personnel bound by confidentiality; your content is not used to train AI models and is not shared with other customers.
- Resilience & recovery: managed backups with defined retention; monitoring and error tracking.
- Vulnerability management: dependency patching and periodic security review.
These measures reflect the service as of the "last updated" date and may be improved over time, provided protection is not materially reduced.
Annex 3 — Authorised sub-processors
The following sub-processors may process Customer Personal Data. Connector providers only receive data if you choose to connect them.
- Supabase — database, authentication, file storage — United Kingdom (London).
- Vercel — application hosting / serverless compute, blob storage, CDN — United States compute (global CDN).
- DigitalOcean — document-editor and analysis worker services — United Kingdom (London).
- Anthropic — AI model processing for drafting and analysis — United States.
- Resend — transactional email delivery — European Union / United States.
- Stripe — billing and payments (merchant of record) — United States / global.
- PostHog — product analytics (only if you accept analytics cookies) — United States.
- Sentry — error and performance monitoring — United States.
- Google, Dropbox, Notion, Atlassian (Confluence) — document-library connectors, only if you connect them — United States / global.
[Confirm each provider's exact processing region and transfer basis before relying on this Annex — see Annex 4.]
Annex 4 — Transfer mechanisms
For sub-processors that process data outside the UK, we rely on one or more of the following, per provider:
- The UK–US Data Bridge (extension of the EU–US Data Privacy Framework), where the provider is certified;
- The UK IDTA, or the UK Addendum to the EU SCCs, incorporated into our contract with that provider, where certification does not apply.
[Record each US provider's specific basis (DPF-certified vs SCC/IDTA) here once verified from their trust pages.]