Skip to content
← Legal

DPA & GDPR

Data-processing roles, customer DPAs, and how to exercise data rights under UK/EU GDPR.

You are viewing the static copy of this page (scripts have not loaded). All content below is complete and current.

This page explains the data-processing relationship between Demiurge Systems Ltd and its customers under the UK GDPR and EU GDPR, and how to put a Data Processing Agreement (DPA) in place.

Controller & processor roles

For personal data you submit about yourself when enquiring or buying, we act as controller (see the Privacy Policy).

For personal data contained in the systems we build and operate for you — for example contacts in a CRM we deploy on your behalf — you are the controller and we act as your processor, processing that data only on your documented instructions.

Data Processing Agreement

Where we act as your processor, a DPA governs that processing. Our DPA covers the subject-matter, duration, nature and purpose of processing, the types of personal data and categories of data subjects, and the obligations below.

A signed, downloadable DPA template is being finalised. Until it is published here, you can request the current DPA and execute it through the process in “How to request a DPA”. We do not present an unsigned placeholder as a binding agreement.

Processing instructions & confidentiality

As processor, we process customer personal data only on your documented instructions, including for transfers, unless required by law. Personnel authorised to process the data are bound by confidentiality obligations.

Security measures

We apply the technical and organisational measures described on our Security page, including encryption in transit, secret management, and least-privilege access. Measures are reviewed as the service evolves.

Subprocessors

We use the subprocessors listed in the Privacy Policy to deliver the service. We impose data-protection terms on each subprocessor consistent with our obligations, and will inform customers of intended changes to give an opportunity to object.

Assisting with data-subject rights

Taking into account the nature of processing, we assist you with appropriate technical and organisational measures to respond to data-subject requests, and to meet your obligations around security, breach notification, and impact assessments.

International transfers

Where processing involves transfers outside the UK/EEA, we rely on appropriate safeguards (such as Standard Contractual Clauses) offered by our subprocessors.

Personal-data breach handling

We maintain a process to detect and respond to personal-data breaches and will notify affected customers without undue delay after becoming aware of a breach affecting their data, with the information needed to meet their own notification duties.

Return & deletion of data

On termination, and at your choice, we delete or return customer personal data processed on your behalf, and delete existing copies unless retention is required by law.

How to request or execute a DPA

To put a DPA in place, or to make a data-processing request, contact ops@demiurge.systems or use /contact and select “DPA / GDPR request”. We will provide the current agreement and walk you through execution.


Demiurge Systems Ltd · Registered in England · 17109558 · Document version 1.0.