Data Processing Addendum

This Data Processing Addendum (“DPA”) forms part of the Terms & Conditions (the “Terms”) between Counter Technologies Ltd(company number 17341153, registered office 14/2e Docklands Business Centre, 10-16 Tiller Road, London E14 8PX) (“Counter”, the “Processor”) and each customer of the Counter service (the “Customer”, the “Controller”). It applies automatically to every Customer and governs Counter’s processing of personal data contained in Customer Data on the Customer’s behalf. We will countersign a copy on request.

Terms defined in the Terms have the same meaning here. “Data Protection Law” means the UK GDPR and the Data Protection Act 2018, as amended.

1. Details of processing

Subject matterProcessing of supplier documents and business communications submitted to, or retrieved by, the Counter service
DurationThe term of the Terms, plus the deletion period in clause 8
Nature and purposeDocument ingestion and AI extraction; price-book construction; discrepancy detection; preparation and sending of supplier correspondence and purchase orders on the Customer’s instruction; reconciliation; reporting; conversational assistant
Categories of data subjectsThe Customer’s personnel and account users; personnel of the Customer’s suppliers and counterparties appearing in documents and correspondence
Types of personal dataNames, business contact details (email, phone), job titles, signatures, and any personal data incidentally contained in business documents and email correspondence. No special-category data is required by the service and the Customer agrees not to submit it deliberately

2. Instructions

Counter will process personal data only on the Customer’s documented instructions, including with regard to international transfers, unless required otherwise by law (in which case Counter will inform the Customer before processing unless the law prohibits it). The Terms, this DPA, and the Customer’s configuration of the service (including enabling or disabling mailbox access, accounting connections, credit correspondence and ordering) constitute the Customer’s complete instructions. Counter will inform the Customer if, in its opinion, an instruction infringes Data Protection Law.

3. Confidentiality

Counter ensures that persons authorised to process the personal data are bound by contractual or statutory obligations of confidentiality.

4. Security

Counter implements and maintains the technical and organisational measures described in Annex 1, and will not materially reduce the overall security of the service during the term.

5. Subprocessors

The Customer gives general written authorisation for Counter to engage the subprocessors listed in the Privacy Policy(“Who we share data with”), which constitutes the current subprocessor list. Counter will:

If the Customer reasonably objects to a new subprocessor on data-protection grounds and the parties cannot resolve the objection within 30 days, the Customer may terminate the affected service on written notice with a pro-rata refund of prepaid fees for the unused period.

6. International transfers

Where processing involves a transfer of personal data outside the UK, Counter will ensure a valid transfer mechanism under Data Protection Law is in place: UK adequacy regulations (including the UK–US Data Bridge where the recipient is certified) or the UK International Data Transfer Addendum to the EU Standard Contractual Clauses, together with any supplementary measures reasonably required.

7. Assistance

Taking into account the nature of the processing, Counter will:

8. Deletion and return

On termination or expiry of the Terms, Counter will, at the Customer’s choice, return Customer personal data (via the export described in the Terms) and delete it from live systems within 90 days, unless retention is required by law. Backup copies expire on their normal rotation. Aggregated and anonymised data that no longer constitutes personal data is outside the scope of this DPA.

9. Audit

Counter will make available to the Customer information reasonably necessary to demonstrate compliance with Article 28 UK GDPR, including summaries of third-party audits or certifications where available, and will allow and contribute to audits (including inspections) conducted by the Customer or its mandated auditor — no more than once per 12-month period, on at least 30 days’ notice, during business hours, without access to other customers’ data, and at the Customer’s cost.

10. Liability and order of precedence

The liability provisions of the Terms apply to this DPA, and liability under this DPA counts toward the cap in the Terms. If this DPA conflicts with the Terms on the subject of personal-data processing, this DPA prevails.

11. Governing law

This DPA is governed by the law of England and Wales.

Annex 1 — Technical and organisational measures

Annex 2 — Subprocessors

The current list of subprocessors, their purposes and locations is maintained in the Privacy Policy(“Who we share data with”) and applies as if set out here.