Data Processing Agreement
Version 1.0 — Last updated 6 August 2026
This Data Processing Agreement (“DPA”) is entered into between CloudRev Intelligence Ltd, a company registered in England and Wales with registered office at 71–75 Shelton Street, London WC2H 9JQ (“CloudRev”, “we”, “us”), and the customer that accepts the Terms and Conditions (“Customer”, “you”).
It forms part of the Terms and Conditions and applies where CloudRev processes personal data on the Customer’s behalf in providing MarginChief. It is made under Article 28 of the UK GDPR.
No signature is required. This DPA takes effect automatically when you accept the Terms and Conditions, and is as binding without a signature as with one. See “How this agreement takes effect” at the end for detail.
Contents
- Definitions and interpretation
- Roles of the parties
- Details of processing
- Processing on documented instructions
- Confidentiality
- Security
- Sub-processors
- International transfers
- Assistance with data subject rights
- Personal data breach
- Data protection impact assessments
- Deletion or return
- Audit and information
- Liability and general
Annex 1 — Details of the processing
Annex 2 — Technical and organisational measures
1. Definitions and interpretation
1.1 In this DPA:
“Customer Personal Data” means personal data contained within Customer Data that CloudRev processes on the Customer’s behalf under the Agreement.
“Data Protection Legislation” means the UK GDPR, the Data Protection Act 2018, the Privacy and Electronic Communications Regulations 2003, and, where applicable to the processing in question, Regulation (EU) 2016/679 (the “EU GDPR”), in each case as amended or replaced.
“EU SCCs” means the standard contractual clauses approved by European Commission Implementing Decision (EU) 2021/914, Module Two (controller to processor) or Module Three (processor to processor) as applicable.
“IDTA” means the International Data Transfer Agreement issued by the Information Commissioner under section 119A of the Data Protection Act 2018, and “UK Addendum” means the International Data Transfer Addendum to the EU SCCs issued under the same section.
“Sub-processor” means any third party engaged by CloudRev to process Customer Personal Data.
“Sub-processor List” means the list published on our Sub-processor List, as updated from time to time.
1.2 “Controller”, “processor”, “data subject”, “personal data”, “processing” and “personal data breach” have the meanings given in the Data Protection Legislation.
1.3 This DPA forms part of, and is subject to, our Terms and Conditions (the “Agreement”). Terms defined in the Agreement have the same meaning here. Where this DPA and the Agreement conflict on the subject matter of data protection, this DPA prevails.
2. Roles of the parties
2.1 The Customer is the controller of Customer Personal Data, or is a processor acting on behalf of a third party controller. CloudRev is the processor, or sub-processor as applicable.
2.2 Where the Customer is itself a processor, the Customer warrants that it has the controller’s authority to enter into this DPA and to give the instructions it gives, and that the controller’s instructions permit the engagement of CloudRev and the Sub-processors on the Sub-processor List.
2.3 CloudRev is a controller in its own right in respect of account administration data, billing records and website usage data. That processing is governed by our Privacy Policy and is outside the scope of this DPA.
2.4 Each party shall comply with its own obligations under the Data Protection Legislation.
3. Details of processing
3.1 The subject matter, duration, nature and purpose of the processing, the types of personal data and the categories of data subjects are set out in Annex 1, as required by Article 28(3) of the UK GDPR.
3.2 The Customer is solely responsible for the accuracy, quality and legality of Customer Personal Data, for the lawful basis on which it was obtained, and for the instructions it gives CloudRev.
4. Processing on documented instructions
4.1 CloudRev shall process Customer Personal Data only on the Customer’s documented instructions, including in relation to transfers to a third country, unless required to do otherwise by law to which CloudRev is subject. Where CloudRev is so required, it shall inform the Customer of that legal requirement before processing, unless the law prohibits that on important grounds of public interest.
4.2 The Agreement, this DPA, the Customer’s use and configuration of the Services, and any further written instructions the Customer gives, together constitute the Customer’s documented instructions.
4.3 CloudRev shall inform the Customer promptly if, in its opinion, an instruction infringes the Data Protection Legislation. CloudRev may suspend performance of the affected instruction until it is withdrawn, amended or confirmed.
4.4 CloudRev shall not sell Customer Personal Data, and shall not use it for its own purposes, including to train, fine-tune or otherwise improve any machine learning model, except to produce Aggregated Data in accordance with the Agreement.
5. Confidentiality
5.1 CloudRev shall ensure that every person it authorises to process Customer Personal Data has committed to confidentiality in writing, or is under an appropriate statutory obligation of confidentiality, and that the obligation survives the end of their engagement.
5.2 CloudRev shall limit access to Customer Personal Data to those personnel who need it to perform the Agreement, on a least-privilege basis, and shall ensure they receive appropriate data protection training.
6. Security
6.1 CloudRev shall implement and maintain the technical and organisational measures set out in Annex 2, which are designed to ensure a level of security appropriate to the risk in accordance with Article 32 of the UK GDPR.
6.2 CloudRev may update the measures in Annex 2 from time to time, provided that no update reduces the overall level of security.
6.3 The Customer is responsible for its own use of the Services, including configuring access controls, managing its Authorised Users, and safeguarding its credentials.
7. Sub-processors
7.1 The Customer gives CloudRev general written authorisation to engage Sub-processors, subject to this clause. The Sub-processors engaged at the date of this DPA are set out in the Sub-processor List.
7.2 CloudRev shall give the Customer at least 30 days’ written notice before engaging a new Sub-processor or replacing an existing one. Notice is given by updating the Sub-processor List and notifying account administrators by email. The Customer may subscribe to notifications by emailing info@marginchief.com.
7.3 The Customer may object to a proposed Sub-processor on reasonable grounds relating to data protection within the notice period. The parties shall discuss the objection in good faith. If it cannot be resolved, the Customer may terminate the affected subscription without penalty and receive a refund of Fees prepaid for any period after termination, as provided in clause 9.6 of the Agreement.
7.4 CloudRev shall impose on each Sub-processor, by written contract, data protection obligations no less protective than those in this DPA, including the obligations in Article 28(3) of the UK GDPR.
7.5 CloudRev remains fully liable to the Customer for the performance of each Sub-processor’s obligations.
7.6 For the avoidance of doubt, Paddle is not a Sub-processor. Paddle acts as merchant of record and sells the subscription to the Customer in its own right, determining the purposes and means of its own processing of payment data. Paddle is an independent controller and its processing is governed by its own privacy policy.
8. International transfers
8.1 Customer Personal Data is stored at rest in the United Kingdom. Processing by the artificial intelligence services described in Annex 1, which extract and interpret the content of documents the Customer uploads, also takes place in the United Kingdom. The single exception is operational telemetry, which is stored in the European Economic Area; the European Economic Area is covered by United Kingdom adequacy regulations.
8.2 The Customer authorises CloudRev to transfer Customer Personal Data, and to permit access to it, outside the United Kingdom in accordance with this clause. Remote access from a third country constitutes a transfer for these purposes.
8.3 CloudRev’s development affiliate, PT Kreasi Wacana Prima (trading as CloudRev Global), is established in Indonesia and its personnel access Customer Personal Data held on CloudRev’s United Kingdom systems for development, maintenance, debugging and technical support. Indonesia is not the subject of UK adequacy regulations. That transfer is governed by an executed IDTA between CloudRev and PT Kreasi Wacana Prima, supported by a documented transfer risk assessment and the additional safeguards described in Annex 2.
8.4 For any other transfer to a country not covered by UK adequacy regulations, CloudRev shall put in place the IDTA or the UK Addendum, supported by a transfer risk assessment. Where the recipient is a United States organisation certified under the UK Extension to the EU-US Data Privacy Framework, CloudRev may rely on that certification instead.
8.5 Where the EU GDPR applies to Customer Personal Data, the EU SCCs are incorporated into this DPA by reference and apply to any transfer to a country without an EU adequacy decision. Module Two applies where the Customer is a controller and Module Three where the Customer is a processor. The optional docking clause applies; clause 11(a) optional redress before an independent dispute resolution body does not apply; the governing law and forum are those of Ireland; Annexes 1 and 2 to this DPA populate Annexes I and II to the EU SCCs, and the Sub-processor List populates Annex III.
8.6 CloudRev shall provide the Customer with a copy of the transfer mechanisms relied on, redacted as necessary to protect commercial confidentiality, within 30 days of written request.
9. Assistance with data subject rights
9.1 The Services provide the Customer with functionality to access, correct, export and delete Customer Personal Data. The Customer shall use that functionality to respond to data subject requests where it is able to do so.
9.2 Taking into account the nature of the processing, CloudRev shall assist the Customer by appropriate technical and organisational measures, insofar as this is possible, in fulfilling the Customer’s obligation to respond to requests to exercise data subject rights under Chapter III of the UK GDPR.
9.3 If CloudRev receives a request directly from a data subject relating to Customer Personal Data, it shall not respond substantively, and shall forward the request to the Customer without undue delay and in any event within 5 working days.
9.4 CloudRev shall provide assistance under this clause at no charge, unless the requests are manifestly unfounded, excessive or repetitive, in which case CloudRev may charge a reasonable fee notified in advance.
10. Personal data breach
10.1 CloudRev shall notify the Customer without undue delay, and in any event within 48 hours, after becoming aware of a personal data breach affecting Customer Personal Data.
10.2 The notification shall describe, to the extent then known: the nature of the breach including the categories and approximate number of data subjects and records concerned; the likely consequences; the measures taken or proposed to address it; and a contact point for further information. Where the information is not all available at once, CloudRev shall provide it in phases without undue further delay.
10.3 CloudRev shall not notify any supervisory authority or data subject of a breach affecting Customer Personal Data on the Customer’s behalf without the Customer’s prior written instruction, unless required to do so by law.
10.4 CloudRev shall provide reasonable assistance to the Customer in investigating, mitigating and remedying the breach, and in meeting the Customer’s obligations under Articles 33 and 34 of the UK GDPR.
11. Data protection impact assessments
11.1 CloudRev shall provide reasonable assistance to the Customer with any data protection impact assessment and any prior consultation with a supervisory authority, in each case relating to the processing under this DPA and taking into account the nature of the processing and the information available to CloudRev, as required by Articles 35 and 36 of the UK GDPR.
12. Deletion or return
12.1 At the Customer’s choice, CloudRev shall delete or return all Customer Personal Data on the expiry or termination of the Agreement, and shall delete existing copies, unless applicable law requires CloudRev to retain it.
12.2 The Customer may export Customer Personal Data at any time during the Subscription Term, and for 30 days after expiry or termination, using the export functionality of the Services. The Customer must notify CloudRev in writing before the end of that 30-day period if it requires return rather than deletion.
12.3 If the Customer gives no instruction, CloudRev shall delete Customer Personal Data within 90 days of expiry or termination, in accordance with clause 13.5 of the Agreement. Backups are deleted on their ordinary cycle and CloudRev shall not restore them save to meet a legal obligation.
12.4 CloudRev shall certify deletion in writing on the Customer’s request.
13. Audit and information
13.1 CloudRev shall make available to the Customer all information reasonably necessary to demonstrate compliance with Article 28 of the UK GDPR and this DPA.
13.2 CloudRev shall allow for and contribute to audits, including inspections, conducted by the Customer or an auditor it mandates. The Customer shall give at least 30 days’ written notice, and audits shall take place no more than once in any 12-month period, during business hours, and in a manner that does not unreasonably disrupt CloudRev’s business. The Customer may audit more frequently following a confirmed personal data breach affecting its Customer Personal Data, or where required by a supervisory authority.
13.3 The Customer shall bear its own costs of an audit, and CloudRev’s reasonable costs of assisting, unless the audit reveals a material breach of this DPA by CloudRev, in which case CloudRev bears its own costs.
13.4 Any auditor must be independent of CloudRev’s competitors and must enter into reasonable confidentiality undertakings. Nothing in this clause requires CloudRev to disclose information relating to other customers, or to grant access that would breach its obligations to third parties.
13.5 CloudRev may satisfy its obligations under clause 13.1 in the first instance by providing a completed security questionnaire, a summary of its technical and organisational measures, and any relevant third-party audit report or certification it holds.
14. Liability and general
14.1 Liability under this DPA is subject to the limitations and exclusions in clause 14 of the Agreement, except to the extent that the Data Protection Legislation prohibits their application.
14.2 This DPA takes effect when the Customer accepts the Agreement, and continues for as long as CloudRev processes Customer Personal Data. Clauses 5, 8, 12, 13 and 14 survive termination.
14.3 CloudRev may amend this DPA on not less than 30 days’ written notice where necessary to comply with the Data Protection Legislation, to reflect a change in approved transfer mechanisms, or to reflect a change in the Services. Where an amendment materially reduces the Customer’s rights, the Customer may terminate the affected subscription in accordance with clause 16.1 of the Agreement.
14.4 This DPA is governed by the law of England and Wales, and clause 15 of the Agreement applies to any dispute arising under it, save that where the EU SCCs apply their own governing law and forum provisions prevail in respect of those clauses.
14.5 Questions about this DPA should be sent to info@marginchief.com.
Annex 1 — Details of the processing
This Annex sets out the information required by Article 28(3) of the UK GDPR, and populates Annex I to the EU SCCs where those apply.
| Item | Detail |
|---|---|
| Subject matter of the processing | The provision of the MarginChief landed cost calculation and inventory cost allocation product, and related support, under the Agreement. |
| Duration of the processing | For the duration of the Subscription Term, plus the 30-day export period and the deletion period described in clause 12. |
| Nature of the processing | Collection, recording, organisation, structuring, storage, retrieval, extraction from uploaded documents, computation, consultation, use, transmission, restriction, erasure and destruction, in each case by automated means, together with manual access by authorised personnel for support and debugging. |
| Purpose of the processing | To provide, secure, maintain, support and improve the Services for the Customer; to calculate landed costs and produce cost records from documents the Customer uploads; and to respond to Customer support requests. |
| Types of personal data | Account and identity data: full name, business email address, job title, employer, user account identifier, authentication metadata, IP address, device and browser information, audit log entries. Personal data contained in uploaded documents: names, job titles, business contact details and signatures of employees and representatives of the Customer and of its suppliers, freight forwarders, customs agents and carriers, as they appear in supplier invoices, purchase orders, bills of lading, freight and customs documentation. Support data: the content of support tickets, error reports, diagnostic logs and correspondence. The parties acknowledge that CloudRev cannot fully specify in advance the personal data contained in documents uploaded by the Customer, because that content is determined by the Customer. |
| Special categories of personal data | None. The Agreement prohibits the Customer from submitting special category personal data within the meaning of Article 9 of the UK GDPR, data relating to criminal convictions and offences, payment cardholder data, or data subject to sector-specific regimes, without CloudRev’s prior written agreement. |
| Categories of data subjects | Employees, officers, contractors and agents of the Customer who hold accounts on or are named within the Services; employees, officers and representatives of the Customer’s suppliers, freight forwarders, customs brokers and carriers whose personal data appears in uploaded documents; and individuals who contact CloudRev’s support function on the Customer’s behalf. |
| Frequency of the transfer | Continuous, for the duration of the Subscription Term. |
| Retention | As set out in clause 12 of this DPA and clause 13.5 of the Agreement. |
Annex 2 — Technical and organisational measures
These are the measures CloudRev applies under clause 6, and they populate Annex II to the EU SCCs where those apply.
| Area | Measures |
|---|---|
| Pseudonymisation and encryption | Data encrypted in transit using TLS 1.2 or higher. Data encrypted at rest using AES-256 or equivalent. Encryption keys controlled by CloudRev and not held by any Sub-processor engaged for development or support. Redacted, pseudonymised or synthetic data used in preference to live data wherever a task permits. |
| Confidentiality of systems | Role-based access control on a least-privilege basis. Named individual accounts only; shared or generic accounts prohibited. Multi-factor authentication on all administrative accounts. Access to production environments via approved VPN or bastion host. Production separated from development and test environments, with no production data in test environments. |
| Integrity of systems | Change management and code review before deployment. Security patching of systems within a period appropriate to the severity of the vulnerability. Input validation and protection against common web application vulnerabilities. |
| Availability and resilience | Managed cloud infrastructure with provider-level redundancy. Routine automated backups. Documented restoration procedure, tested periodically. |
| Restoring availability after an incident | Documented incident response procedure covering detection, containment, eradication, recovery and post-incident review. Backup restoration tested at least annually. |
| Testing and evaluation of measures | Periodic review of access rights and of these measures. Review of the Sub-processor List and of transfer risk assessments at least annually. |
| Access control to premises and systems | No CloudRev office holds Customer Personal Data. All access is remote, authenticated and logged. Devices used to access Customer Personal Data require full disk encryption, automatic screen lock and current endpoint protection. Removable media is disabled or blocked. |
| Controls for support and debugging access | Access to Customer Personal Data in production is granted to named individuals for a specific issue, is time-limited, and is revoked automatically on expiry or on closure of the related ticket. All access to production environments is logged and logs are retained for not less than 12 months. Personnel must not export, download or retain Customer Personal Data outside CloudRev’s United Kingdom systems, and must not transmit it to any third-party service, including any generative artificial intelligence service or code assistant, that CloudRev has not approved in writing. |
| Personnel controls | Written confidentiality undertakings surviving the end of engagement. Data protection training before access is granted and annually thereafter. Access revoked within 24 hours of an individual ceasing to require it. A current written list of individuals authorised to access Customer Personal Data is maintained and available to the Customer on request. |
| Governance | A named individual is accountable for data protection. Records of processing are maintained. Sub-processor contracts impose obligations no less protective than this DPA. |
Annex 3 — Sub-processors
The current list of Sub-processors, with each one’s country of processing and the transfer safeguard that applies, is published on our Sub-processor List and forms part of this DPA.
How this agreement takes effect
This DPA takes effect automatically when the Customer accepts the Terms and Conditions, and applies for as long as CloudRev processes Customer Personal Data on the Customer’s behalf.
No signature is required. An unsigned DPA published in this way is as binding on CloudRev as a signed one, and Article 28 of the UK GDPR does not require a handwritten or electronic signature, only that the arrangement is in writing.
Each version of this DPA is published with a version number and date. The version in force when the Customer accepts the Terms and Conditions is the version that applies, and superseded versions remain available.
If your organisation has questions about this DPA, or requires further information for its own records, email info@marginchief.com.
CloudRev Intelligence Ltd, 71–75 Shelton Street, London WC2H 9JQ, United Kingdom. Registered in England and Wales, company number 17234811.
Questions: info@marginchief.com