DATA PROCESSING AGREEMENT
Version 3.0 | Last Updated 9th April 2026
Supplier (Processor)
RIVER AI & DIGITAL LIMITED, with company number: 16673730, registered address: 71-75 Shelton Street, London, WC2H 9JQ, contactable by email: notices@riverai.co.uk
Customer (Controller)
As named in the Order Form.
Each of the parties shall be referred to as a Party or together, the Parties.
Processing details are set out in Schedule 1.
Background
The Supplier provides Services to the Customer and may be required to process Customer Personal Data to fulfil the Purpose.
This Agreement sets out the terms on which the Supplier will process Customer Personal Data in accordance with Data Protection Laws.
1. Definitions and Interpretation
In this Agreement, unless the context otherwise requires, the following expressions have the following meanings:
Term | Definition |
|---|---|
Agreement | means this Data Processing Agreement (DPA), including Schedule 1 and any Schedules attached to it, and forms part of the Contract Details. |
Contract Details | means the agreement between the Parties described in the Order Form and any Statement of Work, and any applicable master/services/subscription terms incorporated by reference. |
Customer Personal Data | means the personal data processed by the Supplier on behalf of the Customer under this Agreement, as described in Schedule 1 and any applicable Statement of Work. |
Data Protection Laws | means all applicable data protection and privacy legislation in force from time to time in: a) the United Kingdom, including the UK GDPR (as defined in the Data Protection Act 2018), the Data Protection Act 2018, and PECR; and b) where applicable, the European Union/EEA, including the EU GDPR, in each case as amended, updated or replaced, together with relevant guidance or codes of practice issued by a DP Regulator. |
DP Regulator | means a competent supervisory authority under Data Protection Laws (in the UK, the Information Commissioner’s Office). |
Personal Data Breach | means a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to personal data. |
Sub-Processor(s) | means any processor engaged by the Supplier (or by any other Sub-Processor) to process Customer Personal Data. |
Standard Contractual Clauses (SCCs) | means the ICO’s International Data Transfer Agreement for the transfer of personal data from the UK and/or the ICO’s International Data Transfer Addendum to EU Commission Standard Contractual Clauses and/or the European Commission’s Standard Contractual Clauses for the transfer of personal data to third countries pursuant to Regulation (EU) 2016/679, or such alternative clauses as may be approved from time to time. |
Terms such as controller, processor, data subject, personal data, processing, and appropriate technical and organisational measures have the meanings given in Data Protection Laws.
Headings do not affect interpretation. References to legislation include amendments and replacements. “Including” shall not be limiting.
In the case of conflict or ambiguity between:
2. Data Protection Roles and Relationship
3. Data Processing Obligations
3.1 Controller instructions. The Supplier shall process Customer Personal Data only on the documented instructions of the Customer, including as necessary to provide the Services and fulfil the Purpose, unless required by applicable law. Where processing is required by law, the Supplier shall (where legally permitted) inform the Customer before processing.
3.2 Notification of unlawful instructions. The Supplier shall notify the Customer if, in its reasonable opinion, an instruction infringes Data Protection Laws.
3.3 Compliance with Customer instructions. The Supplier shall promptly comply with any reasonable written instruction from the Customer requiring the Supplier to amend, transfer, delete or otherwise process Customer Personal Data, or to stop, mitigate or remedy any unauthorised processing.
3.4 Security measures. The Supplier shall implement appropriate technical and organisational measures to protect Customer Personal Data against unauthorised or unlawful processing and against accidental loss, destruction or damage. Such measures shall include, as appropriate:
3.5 Confidentiality and personnel. The Supplier shall ensure that persons authorised to process Customer Personal Data:
3.6 Data subject requests. The Supplier shall, to the extent permitted by law:
3.7 Assistance. Taking into account the nature of the processing and information available to the Supplier, the Supplier shall provide reasonable assistance to the Customer to support compliance with Data Protection Laws in relation to:
Where assistance materially exceeds the scope of the Services, the Supplier may charge at its reasonable standard rates unless the assistance is required due to the Supplier’s breach.
4. Personal Data Breach
4.1 The Supplier shall notify the Customer without undue delay and, where feasible, within forty-eight (48) hours after becoming aware of a Personal Data Breach affecting Customer Personal Data.
4.2 Such notification shall include, to the extent available at the time of notification and supplemented as further information becomes available:
4.3 Immediately following any Personal Data Breach, the Parties shall co-ordinate with each other to investigate the matter. The Supplier shall reasonably co-operate with the Customer in the Customer’s handling of the matter.
4.4 The Supplier agrees, subject to any obligation under applicable law, that the Customer shall have the sole right to determine:
5. Sub-Processors
5.1 General authorisation. The Customer gives prior general authorisation for the Supplier to appoint Sub-Processors.
5.2 Flow-down terms. The Supplier shall ensure that Sub-Processors are engaged under written terms that impose data protection obligations materially similar to those set out in this Agreement and required by Data Protection Laws.
5.3 Responsibility. The Supplier shall remain responsible for the acts and omissions of its Sub-Processors as if they were its own.
5.4 Changes and objections. The Supplier shall inform the Customer of any intended changes concerning the addition or replacement of Sub-Processors. The Customer may object on reasonable grounds relating to data protection or security within fifteen (15) days of notice. The Parties shall work in good faith to resolve the objection.
5.5 Approved Sub-Processors. The Supplier’s Sub-Processors are set out in Schedule 2 and may be updated in accordance with clause 5.4.
6. International Transfers
the UK International Data Transfer Agreement (IDTA) and/or UK Addendum to the EU SCCs;
EU Standard Contractual Clauses (SCCs); and/or
an adequacy decision/regulation, together with supplementary measures where required.
7. Liability
7.1 Neither Party excludes or limits liability for:
7.2 Subject to clause 7.1, the Parties’ total aggregate liability arising under or in connection with this Agreement and/or Data Protection Laws shall be limited to £500,000, unless the Contract Details set a higher cap (in which case the higher cap applies).
8. Audit
8.1 The Supplier shall maintain appropriate records of processing activities carried out on behalf of the Customer as required by Data Protection Laws.
8.2 Upon written request, the Supplier shall make available to the Customer information reasonably necessary to demonstrate compliance with this Agreement.
8.3 Audit right. The Customer (or its appointed independent auditor) may conduct an audit of the Supplier’s compliance with this Agreement no more than once per year, on at least thirty (30) days’ prior written notice, during normal business hours, and in a manner that minimises disruption and does not compromise security or other customers’ confidentiality.
8.4 Breach exception. In the event of an actual or reasonably suspected Personal Data Breach affecting Customer Personal Data, the Customer may request an additional audit limited to matters relevant to that breach.
8.5 Audit method and costs. The Supplier may satisfy audit requests by providing reasonable evidence such as security attestations (e.g., Cyber Essentials), policies, questionnaires, and/or remote review before any on-site inspection. The Customer bears its audit costs. The Supplier may charge reasonable time/cost for supporting audits beyond the standard evidence package, except where the audit is required due to the Supplier’s breach.
9. Termination and Effect of Termination
9.1 This Agreement remains in effect for the Duration of Processing.
9.2 Upon termination or expiry of the Services, and at the Customer’s written direction, the Supplier shall delete (so far as technically possible) or return Customer Personal Data and any copies within sixty (60) days of termination, unless:
9.3 Customer Personal Data shall be considered deleted when it can no longer be used by the Supplier for any processing purposes and is not reasonably retrievable from live systems (excluding routine backups retained for disaster recovery, which will be overwritten in accordance with backup retention schedules).
9.4 Any provision of this Agreement that expressly or by implication should come into or continue in force on or after termination in order to protect Customer Personal Data shall remain in full force and effect.
10. Indemnity
10.1 The Supplier shall indemnify the Customer for losses, claims, damages, liabilities, fines, penalties, costs and expenses arising out of or in connection with a breach by the Supplier of its obligations under this Agreement.
10.2 For the avoidance of doubt, the liability cap in clause 7.2 applies to the indemnity in this clause 10 (to the extent permitted by law).
11. General
11.1 Costs. Each Party is responsible for its own legal and other costs in relation to the preparation and performance of this Agreement.
11.2 Survival. The Parties intend clauses 1, 6, 7, 8, 9, 10 and 11 and any clauses required for their interpretation to survive termination.
11.3 Relationship. The Parties are independent contractors and nothing creates a partnership, agency, or employment relationship.
11.4 Third Party Rights. No third party has rights under the Contracts (Rights of Third Parties) Act 1999 to enforce this Agreement.
11.5 Assignment. No Party may assign or transfer this Agreement without the other Party’s prior written consent, except as expressly permitted in the Contract Details.
11.6 Entire Agreement. This Agreement and documents referred to in it contain the whole agreement between the Parties regarding its subject matter and supersede prior understandings. Nothing limits liability for fraud.
11.7 Variation. No variation is valid unless in writing and signed by authorised signatories of both Parties.
11.8 Severability. If any provision is invalid or unenforceable, it will be modified to the minimum extent necessary to make it enforceable, and the remainder continues in effect.
11.9 Waiver. A failure or delay to exercise a right is not a waiver.
11.10 Notices. Notices must be in writing and sent to the address/email in the Contract Details. UK letters are deemed delivered three (3) business days after posting. Emails are deemed delivered the same day (or next business day if sent after 5pm or on a non-business day at the recipient’s location).
11.11 Counterparts. This Agreement may be signed in counterparts and by electronic signature.
11.12 Governing Law and Jurisdiction. This Agreement is governed by the laws of England and Wales and subject to the exclusive jurisdiction of the courts of England and Wales.
Agreement Acceptance
By signing the Order Form, the Parties agree to the terms of this Agreement with effect from the date the Order Form is signed by both Parties.
Schedule 1 — Processing Details
Field | Details |
|---|---|
Purpose | For the Supplier to provide AI, digital and IT services to the Customer, which may include AI consulting, solution design, software development, data analytics, AI/ML implementation, cloud engineering, security engineering, support, and managed services (the Services). |
Scope and Nature of Processing | The Supplier may process Customer Personal Data to the extent necessary to deliver the Services, including accessing, collecting, recording, organising, structuring, storing, retrieving, using, disclosing (only as permitted), aligning/combining, restricting, erasing and destroying Customer Personal Data, primarily in digital form and within systems used to deliver the Services. |
Categories of Data Subject | The Customer’s employees, consultants, contractors, and (where applicable) the Customer’s potential and actual customers/end users, suppliers, and other individuals as set out in the Statement of Work. |
Categories of Personal Data | As determined by the Customer and the Services, and may include: • Names and business contact details (e.g., email address, telephone number, job title) • User identifiers (e.g., usernames, IDs), IP addresses, device/technical identifiers • System audit logs, access logs, security/event logs • Communications content / user interaction data submitted to or generated within solutions (where applicable) • Any additional categories expressly set out in the Statement of Work / Order Form |
Categories of Special Category Data | By default, the Services are not intended to process special category data or criminal offence data. If such data is required for a specific use case, it must be explicitly documented in a Statement of Work and subject to additional safeguards agreed in writing. |
Duration of Processing | For the term during which the Supplier provides the Services to the Customer, plus any return/deletion period set out in this Agreement. |
Responsible Person | Supplier privacy contact: Head of IT & Service Operations Email: notices@riverai.co.uk (for the attention of “Data Protection”) |
Schedule 2 — Approved Sub-Processors
Service Delivery Sub-Processors
Name | Description | Data Location | Date Added |
|---|---|---|---|
Microsoft | Cloud infrastructure and productivity services. Includes Microsoft 365 and Microsoft Azure supporting solution delivery (hosting, compute, storage, identity, security services). | EU | 10 Oct 2025 |
FireFlies | AI meeting transcription and conversation intelligence platform used to record, transcribe and analyse customer meetings. | EU | 10 Oct 2025 |
OneReach | Conversational AI and automation platform used to design/deploy AI-driven workflows and orchestration solutions (where contracted). | EU | 1 Nov 2025 |
OpenAI | AI model provider used for model inference (e.g., summarisation, classification, generation) embedded within customer solutions. May process prompts/inputs and outputs submitted via API. | As per configured region / vendor terms | 2 Feb 2026 |
Atlassian | Project management and collaboration tools (e.g., Jira, Confluence) used for service delivery management, documentation and support workflows. | EU | 2 Feb 2026 |
GitHub | Source control/CI tool used for code hosting and CI/CD where applicable. | EU | 2 Apr 2026 |
Internal Business Systems
The following systems are primarily used for Supplier business administration. Where these systems process Customer business contact details (e.g., named contacts for account management, invoicing, or contractual administration), such processing is limited to what is necessary for those purposes and does not involve processing Customer content/data sets unless explicitly agreed.
Name | Description | Data Location | Date Added |
|---|---|---|---|
Pipedrive | CRM used for sales pipeline and account/contact management. | EU | 10 Oct 2025 |
Revolut | Banking/financial services provider used for payments. | EU | 10 Oct 2025 |
Xero | Accounting/invoicing and financial reporting. | EU | 10 Oct 2025 |
Canva | Online design platform used for creating marketing materials, presentations, and internal communications assets. | US | 10 Oct 2025 |
Granola | AI-powered meeting assistant used to capture, transcribe and summarise internal and client meetings. | EU | 20 Feb 2026 |
Claude | AI assistant used for drafting, summarising, and analysing business documents, communications, and internal workflows. | US | 2 Apr 2026 |
