Data Processing Agreement

Last updated: 5 September 2026

1. Parties and scope

This Data Processing Agreement (“DPA”) forms part of the agreement between the customer and NETRIAM LTD, company number 17432800, of Unit C, Blackett Street, Manchester, United Kingdom, M12 6AE. It applies where Netriam processes personal data on the customer's behalf in providing the service.

The customer is the controller and Netriam is the processor, except where either party acts in another capacity under applicable data-protection law. Terms including personal data, processing, controller, processor and data subject have the meanings given in UK data-protection law.

2. Processing details

The subject matter is delivery, operation, security and support of Netriam. Processing lasts for the customer's use of the service and the applicable deletion or retention period. Its nature and purpose include hosting, storing, transmitting, extracting, structuring, reviewing, securing, supporting and exporting customer-submitted content.

Personal data may include names, work contact details, roles, identifiers, signatures, images, document content, audit information and any other personal data the customer chooses to submit. Data subjects may include customer users, workers, contractors, clients, suppliers, visitors and other people identified in customer content.

3. Customer instructions

Netriam will process personal data only on the customer's documented instructions, including instructions expressed through authorised use of the service, unless applicable law requires otherwise. If legally permitted, Netriam will notify the customer before processing required by law. Netriam will inform the customer if an instruction appears to infringe applicable data-protection law.

The customer is responsible for the lawfulness, accuracy and quality of submitted data, providing required notices, obtaining any necessary permissions, and ensuring its instructions comply with law.

4. Confidentiality and security

Netriam will ensure that people authorised to process personal data are bound by confidentiality obligations. Netriam will maintain appropriate technical and organisational measures proportionate to the risk, including access controls, tenant isolation, authentication, logging, encryption in transit, provider security controls, operational monitoring and processes for vulnerability and incident management.

5. Sub-processors

The customer gives general authorisation for Netriam to use sub-processors needed to provide the service. Current service providers include Supabase for database, authentication and storage; Vercel for application hosting; Anthropic for AI processing; Stripe for payments and subscription management; and Resend for transactional email.

Netriam will impose appropriate data-protection obligations on sub-processors and remains responsible for their processing to the extent required by law. Netriam will provide reasonable notice of a material new sub-processor. A customer may raise a reasonable data-protection objection by emailing support@netriam.com.

6. Assistance and incidents

Taking account of the nature of processing and information available to it, Netriam will provide reasonable assistance with data-subject requests, security obligations, personal-data-breach notifications, data-protection impact assessments and regulator consultations. Netriam will notify the customer without undue delay after becoming aware of a personal-data breach affecting customer-controlled personal data and will provide information reasonably available to support the customer's response.

7. Return and deletion

During the service, the customer may use available export and deletion controls. At the end of the service, Netriam will delete or return personal data in accordance with the customer's choice and the agreed retention lifecycle, unless law requires continued storage. Residual encrypted backups may remain until the applicable backup cycle expires and remain protected during that period.

8. Information and audits

Netriam will make available information reasonably necessary to demonstrate compliance with applicable processor obligations. On reasonable written notice, it will support a proportionate audit or inspection, normally through current documentation and remote evidence first. Audits must protect other customers, security and confidentiality and must not unreasonably disrupt the service. The customer is responsible for its audit costs unless an audit identifies a material breach by Netriam.

9. International transfers

Where processing involves a restricted international transfer, Netriam will use an applicable lawful transfer mechanism, such as UK adequacy regulations, the UK International Data Transfer Agreement or the UK Addendum to approved standard contractual clauses, together with supplementary measures where appropriate.

10. General

If this DPA conflicts with the main service terms on processing personal data, this DPA takes priority for that conflict. The liability and governing-law provisions of the main service terms apply to this DPA. Questions may be sent to support@netriam.com.