Data Processing Addendum
Last updated: 28 July 2026 · Version 1.0
This Data Processing Addendum (“DPA”) forms part of the Terms & Conditions (the “Terms”) between Counter Technologies Ltd(company number 17341153, registered office 14/2e Docklands Business Centre, 10-16 Tiller Road, London E14 8PX) (“Counter”, the “Processor”) and each customer of the Counter service (the “Customer”, the “Controller”). It applies automatically to every Customer and governs Counter’s processing of personal data contained in Customer Data on the Customer’s behalf. We will countersign a copy on request.
Terms defined in the Terms have the same meaning here. “Data Protection Law” means the UK GDPR and the Data Protection Act 2018, as amended.
1. Details of processing
| Subject matter | Processing of supplier documents and business communications submitted to, or retrieved by, the Counter service |
|---|---|
| Duration | The term of the Terms, plus the deletion period in clause 8 |
| Nature and purpose | Document ingestion and AI extraction; price-book construction; discrepancy detection; preparation and sending of supplier correspondence and purchase orders on the Customer’s instruction; reconciliation; reporting; conversational assistant |
| Categories of data subjects | The Customer’s personnel and account users; personnel of the Customer’s suppliers and counterparties appearing in documents and correspondence |
| Types of personal data | Names, business contact details (email, phone), job titles, signatures, and any personal data incidentally contained in business documents and email correspondence. No special-category data is required by the service and the Customer agrees not to submit it deliberately |
2. Instructions
Counter will process personal data only on the Customer’s documented instructions, including with regard to international transfers, unless required otherwise by law (in which case Counter will inform the Customer before processing unless the law prohibits it). The Terms, this DPA, and the Customer’s configuration of the service (including enabling or disabling mailbox access, accounting connections, credit correspondence and ordering) constitute the Customer’s complete instructions. Counter will inform the Customer if, in its opinion, an instruction infringes Data Protection Law.
3. Confidentiality
Counter ensures that persons authorised to process the personal data are bound by contractual or statutory obligations of confidentiality.
4. Security
Counter implements and maintains the technical and organisational measures described in Annex 1, and will not materially reduce the overall security of the service during the term.
5. Subprocessors
The Customer gives general written authorisation for Counter to engage the subprocessors listed in the Privacy Policy(“Who we share data with”), which constitutes the current subprocessor list. Counter will:
- give at least 30 days’ notice (by email or in the dashboard) before adding or replacing a subprocessor that processes Customer personal data;
- impose data-protection obligations on each subprocessor materially equivalent to those in this DPA; and
- remain liable to the Customer for the subprocessor’s performance.
If the Customer reasonably objects to a new subprocessor on data-protection grounds and the parties cannot resolve the objection within 30 days, the Customer may terminate the affected service on written notice with a pro-rata refund of prepaid fees for the unused period.
6. International transfers
Where processing involves a transfer of personal data outside the UK, Counter will ensure a valid transfer mechanism under Data Protection Law is in place: UK adequacy regulations (including the UK–US Data Bridge where the recipient is certified) or the UK International Data Transfer Addendum to the EU Standard Contractual Clauses, together with any supplementary measures reasonably required.
7. Assistance
Taking into account the nature of the processing, Counter will:
- assist the Customer with appropriate technical and organisational measures to respond to data-subject requests (access, rectification, erasure, restriction, portability, objection), and forward to the Customer without undue delay any such request Counter receives directly;
- assist the Customer with its obligations regarding security, breach notification, data protection impact assessments and prior consultation under Articles 32–36 UK GDPR; and
- notify the Customer without undue delay, and in any event within 48 hours, after becoming aware of a personal data breach affecting Customer personal data, providing the information reasonably required for the Customer’s own notification obligations.
8. Deletion and return
On termination or expiry of the Terms, Counter will, at the Customer’s choice, return Customer personal data (via the export described in the Terms) and delete it from live systems within 90 days, unless retention is required by law. Backup copies expire on their normal rotation. Aggregated and anonymised data that no longer constitutes personal data is outside the scope of this DPA.
9. Audit
Counter will make available to the Customer information reasonably necessary to demonstrate compliance with Article 28 UK GDPR, including summaries of third-party audits or certifications where available, and will allow and contribute to audits (including inspections) conducted by the Customer or its mandated auditor — no more than once per 12-month period, on at least 30 days’ notice, during business hours, without access to other customers’ data, and at the Customer’s cost.
10. Liability and order of precedence
The liability provisions of the Terms apply to this DPA, and liability under this DPA counts toward the cap in the Terms. If this DPA conflicts with the Terms on the subject of personal-data processing, this DPA prevails.
11. Governing law
This DPA is governed by the law of England and Wales.
Annex 1 — Technical and organisational measures
- Encryption — personal data encrypted in transit (TLS) and at rest.
- Access control — production access restricted to authorised personnel; authentication required on all administrative interfaces; internal service-to-service calls authenticated with secrets compared in constant time.
- Tenant segregation — Customer Data segregated per company at the application layer; automated checks enforce tenant scoping on every code change.
- Secure development — code review on all changes; automated dependency, secret-leak and static-analysis scanning in CI.
- Infrastructure — hosted on the providers listed in the Privacy Policy, each maintaining its own certified security programme (e.g. SOC 2).
- Monitoring — centralised error monitoring and operational alerting.
- Resilience — managed database with automated backups on a rolling schedule.
- Personnel — confidentiality obligations for all personnel with data access.
Annex 2 — Subprocessors
The current list of subprocessors, their purposes and locations is maintained in the Privacy Policy(“Who we share data with”) and applies as if set out here.