Workfree Limited (trading as PAIDD) | Company Number: 13799043
128 City Road, London, EC1V 2NX, United Kingdom
hello@paidd.io | www.paidd.io
This Data Processing Agreement ("DPA") forms part of the Service Agreement between you (the "Controller") and Workfree Limited trading as PAIDD (the "Processor") and governs the processing of personal data in connection with our early payment discount platform services.
This DPA ensures compliance with applicable data protection laws, including the UK General Data Protection Regulation (UK GDPR), the EU General Data Protection Regulation (EU GDPR) and the Data Protection Act 2018.
This DPA applies when:
Nature and purpose. PAIDD processes personal data for platform authentication, service delivery, system integration with Customer's accounting and ERP systems, customer support, security monitoring and fraud prevention, and legal compliance.
Duration. Processing continues for the term of the Service Agreement and the retention periods set out in section 9.
Retention periods. Active service period: duration of the subscription. Post-termination: 30 days read-only access for export; all personal data deleted 90 days after termination. Session data: deleted when the session ends or within 30 days. Support records: 2 years. PAIDD's own accounting records relating to fees charged to Customer are retained for 6 years as required by UK tax law; this does not extend to personal data processed on Customer's behalf.
Customer obligations as Controller. Customer warrants that it has a lawful basis for processing all personal data provided to PAIDD, has authority to provide it, will obtain necessary consents where required, and will maintain records of processing activities. Customer will provide appropriate privacy notices to suppliers and contacts, inform data subjects of PAIDD's involvement in processing, and handle data subject requests regarding their rights.
Processing instructions. PAIDD processes personal data only according to Customer's documented instructions, does not process personal data for its own purposes except as legally required, immediately informs Customer if instructions appear to violate applicable law, and maintains records of all processing carried out on Customer's behalf.
Personnel. PAIDD ensures that all personnel authorised to process personal data are bound by a duty of confidentiality and have received appropriate data protection training.
Assistance. PAIDD assists Customer, taking into account the nature of processing and the information available to it, in complying with its obligations in relation to security, breach notification, data protection impact assessments, and prior consultation with a supervisory authority.
Compliance. PAIDD makes available to Customer all information necessary to demonstrate compliance with this DPA, and immediately informs Customer if it can no longer meet its obligations.
Authorisation and notice. Customer authorises the sub-processors listed below. PAIDD will give Customer at least 30 days' notice of any intended addition or replacement of a sub-processor, and Customer may object on reasonable data protection grounds. Each sub-processor is bound by written terms offering the same level of protection as this DPA.
| Sub-processor | Service | Location |
|---|---|---|
| DigitalOcean | Platform hosting | EU |
| Amazon Web Services | File storage | EU |
| SendGrid | Email delivery | US (with SCCs) |
| Twilio | WhatsApp and SMS notifications | US (with SCCs) |
| Stripe | Payment processing for fees | US/EU (with SCCs) |
| Sentry | Error monitoring | US (with SCCs) |
| Intercom | Support and analytics | US (with SCCs) |
| Google Workspace | Business communications | EU/UK |
When PAIDD receives a data subject request, we will:
For personal data breaches, PAIDD will:
Upon service termination, PAIDD will provide personal data in a structured format (CSV, JSON), 30 days read-only access for export and migration, reasonable technical assistance with data transfer, and confirmation of successful transfer before deletion. At Customer's choice, PAIDD deletes or returns all personal data; all personal data is deleted 90 days after termination unless retention is required by law.
Personal data transferred from the European Economic Area to PAIDD's systems in the United Kingdom is transferred on the basis of the European Commission's adequacy decision for the United Kingdom of 19 December 2025. Where personal data is transferred onward to a country without an adequacy decision, PAIDD puts in place Standard Contractual Clauses and, where applicable, the UK International Data Transfer Addendum.
PAIDD also applies adequacy decisions where available, supplementary safeguards where required, and reviews transfer risks regularly.
Customer may:
For questions about this Data Processing Agreement, contact hello@paidd.io.