Legal

Data Processing Agreement

Version 2.0  ·  Effective September 2026

← Back to Legal Hub

Workfree Limited (trading as PAIDD) | Company Number: 13799043
128 City Road, London, EC1V 2NX, United Kingdom
hello@paidd.io | www.paidd.io

1. Agreement Overview

This Data Processing Agreement ("DPA") forms part of the Service Agreement between you (the "Controller") and Workfree Limited trading as PAIDD (the "Processor") and governs the processing of personal data in connection with our early payment discount platform services.

This DPA ensures compliance with applicable data protection laws, including the UK General Data Protection Regulation (UK GDPR), the EU General Data Protection Regulation (EU GDPR) and the Data Protection Act 2018.

This DPA applies when:

  • Customer uses the Platform for invoice processing that involves personal data
  • Contact information of suppliers, vendors, or individuals is processed through the Platform
  • PAIDD acts as processor on Customer's behalf for personal data
  • Processing occurs within PAIDD's systems during service delivery

2. Scope of Personal Data Processing

Business contact information

  • Supplier contacts: names and email addresses of supplier representatives
  • Customer users: names and email addresses of platform users within Customer's organisation
  • Invoice contacts: contact details when included in invoice data by Customer
  • Communication records: email communications sent through platform notifications
  • Telephone numbers, where Customer enables WhatsApp or SMS notifications

Platform usage information

  • Authentication data: login credentials and session information
  • Access logs: platform usage timestamps and feature access
  • Support communications: records of customer support interactions where personal data is involved

What we don't process

  • Extensive personal data databases or profiles
  • Special category data
  • Personal data analytics beyond basic platform usage
  • Cross-platform tracking or behavioural profiling
  • Personal financial information

Categories of data subjects

  • Supplier representatives: employees and contacts of Customer's suppliers
  • Customer employees: users of the Platform within Customer's organisation
  • Individual suppliers: sole traders and individual contractors
  • Invoice contacts: individuals designated for invoice-related communications

3. Processing Details

Nature and purpose. PAIDD processes personal data for platform authentication, service delivery, system integration with Customer's accounting and ERP systems, customer support, security monitoring and fraud prevention, and legal compliance.

Duration. Processing continues for the term of the Service Agreement and the retention periods set out in section 9.

Retention periods. Active service period: duration of the subscription. Post-termination: 30 days read-only access for export; all personal data deleted 90 days after termination. Session data: deleted when the session ends or within 30 days. Support records: 2 years. PAIDD's own accounting records relating to fees charged to Customer are retained for 6 years as required by UK tax law; this does not extend to personal data processed on Customer's behalf.

4. Controller and Processor Obligations

Customer obligations as Controller. Customer warrants that it has a lawful basis for processing all personal data provided to PAIDD, has authority to provide it, will obtain necessary consents where required, and will maintain records of processing activities. Customer will provide appropriate privacy notices to suppliers and contacts, inform data subjects of PAIDD's involvement in processing, and handle data subject requests regarding their rights.

Processing instructions. PAIDD processes personal data only according to Customer's documented instructions, does not process personal data for its own purposes except as legally required, immediately informs Customer if instructions appear to violate applicable law, and maintains records of all processing carried out on Customer's behalf.

Personnel. PAIDD ensures that all personnel authorised to process personal data are bound by a duty of confidentiality and have received appropriate data protection training.

Assistance. PAIDD assists Customer, taking into account the nature of processing and the information available to it, in complying with its obligations in relation to security, breach notification, data protection impact assessments, and prior consultation with a supervisory authority.

Compliance. PAIDD makes available to Customer all information necessary to demonstrate compliance with this DPA, and immediately informs Customer if it can no longer meet its obligations.

5. Security Measures

  • Data in transit: TLS 1.3 encryption for all connections and data transfers
  • Data at rest: encrypted storage
  • Access controls: role-based access with multi-factor authentication
  • Session security: secure session management with automatic logout
  • Network security: firewalls, intrusion detection, and monitoring
  • API security: secure integration protocols with Customer systems
  • Audit logging: comprehensive logs of data access and processing activities

6. Sub-Processing

Authorisation and notice. Customer authorises the sub-processors listed below. PAIDD will give Customer at least 30 days' notice of any intended addition or replacement of a sub-processor, and Customer may object on reasonable data protection grounds. Each sub-processor is bound by written terms offering the same level of protection as this DPA.

Sub-processor Service Location
DigitalOceanPlatform hostingEU
Amazon Web ServicesFile storageEU
SendGridEmail deliveryUS (with SCCs)
TwilioWhatsApp and SMS notificationsUS (with SCCs)
StripePayment processing for feesUS/EU (with SCCs)
SentryError monitoringUS (with SCCs)
IntercomSupport and analyticsUS (with SCCs)
Google WorkspaceBusiness communicationsEU/UK

7. Data Subject Rights

When PAIDD receives a data subject request, we will:

  • Notify Customer within 48 hours
  • Provide details of the personal data processed
  • Support Customer in responding to the request
  • Extract relevant data in a usable format where possible

8. Data Breach Response

For personal data breaches, PAIDD will:

  • Contain and assess the breach immediately upon discovery
  • Notify Customer without undue delay and in any event within 24 hours of becoming aware
  • Provide an initial assessment of breach scope and impact
  • Implement immediate remediation measures

9. Data Return and Deletion

Upon service termination, PAIDD will provide personal data in a structured format (CSV, JSON), 30 days read-only access for export and migration, reasonable technical assistance with data transfer, and confirmation of successful transfer before deletion. At Customer's choice, PAIDD deletes or returns all personal data; all personal data is deleted 90 days after termination unless retention is required by law.

10. International Transfers

Personal data transferred from the European Economic Area to PAIDD's systems in the United Kingdom is transferred on the basis of the European Commission's adequacy decision for the United Kingdom of 19 December 2025. Where personal data is transferred onward to a country without an adequacy decision, PAIDD puts in place Standard Contractual Clauses and, where applicable, the UK International Data Transfer Addendum.

PAIDD also applies adequacy decisions where available, supplementary safeguards where required, and reviews transfer risks regularly.

11. Compliance and Audit

Customer may:

  • Request compliance documentation and reports
  • Conduct audits with reasonable advance notice (30 days)
  • Engage qualified third parties for audits
  • Review security certifications and assessment reports

12. Contact

For questions about this Data Processing Agreement, contact hello@paidd.io.