Last updated: 30 July 2026
This Data Processing Agreement ("DPA") forms part of the Terms of Service (the "Agreement") between the Customer ("Controller", "you") and Gibney Technology Enterprises Limited ("ClientCollect", "Processor", "we") and applies to our processing of personal data on your behalf when you use the Service. Where this DPA conflicts with the Agreement on data-protection matters, this DPA prevails.
Terms such as "personal data", "processing", "controller", "processor", "data subject", "personal data breach" and "supervisory authority" have the meanings given in the EU General Data Protection Regulation (Regulation (EU) 2016/679, "GDPR"). "Data Protection Law" means the GDPR and applicable implementing laws.
For personal data that you and your clients submit into the Service ("Customer Data"), you are the controller and ClientCollect is the processor. You are responsible for the lawfulness of your instructions and for having a lawful basis for the processing. Personal data that ClientCollect controls — for example, your account details — is governed by our Privacy Policy, not this DPA.
We process Customer Data only on your documented instructions — including the Agreement, your configuration and use of the Service, and any written instructions you give — except where required by law, in which case we will inform you unless the law prohibits it. If we believe an instruction infringes Data Protection Law, we will inform you.
We ensure that personnel authorised to process Customer Data are bound by appropriate obligations of confidentiality.
We implement appropriate technical and organisational measures to ensure a level of security appropriate to the risk, as summarised in Annex 2.
You provide general authorisation for us to engage sub-processors to process Customer Data. Current sub-processors are listed in Annex 3. We impose data-protection obligations on each sub-processor no less protective than those in this DPA, and we remain responsible for their performance. We will give you advance notice of any intended addition or replacement of a sub-processor and a reasonable opportunity to object on reasonable data-protection grounds.
Where processing involves transferring Customer Data outside the EEA, we rely on an adequacy decision or appropriate safeguards, including the European Commission's Standard Contractual Clauses, which are incorporated by reference where applicable.
Taking into account the nature of the processing, we assist you by appropriate technical and organisational measures, insofar as possible, to respond to requests from data subjects exercising their rights under the GDPR. Where a data subject contacts us directly about Customer Data, we will refer them to you.
We assist you in ensuring compliance with your obligations relating to security, breach notification, data-protection impact assessments and prior consultation, taking into account the nature of processing and the information available to us.
We notify you without undue delay after becoming aware of a personal data breach affecting Customer Data, and provide the information reasonably available to us to help you meet your own notification obligations.
On termination of the Service, we will, at your choice, delete or return Customer Data and delete existing copies, unless law requires storage. Data held in backups is deleted in line with our backup cycle.
We make available to you the information necessary to demonstrate compliance with Article 28 and allow for and contribute to audits, including inspections, conducted by you or an auditor you mandate, subject to reasonable confidentiality, security, notice and frequency conditions.
Each party's liability under this DPA is subject to the limitations of liability set out in the Agreement.
| Item | Detail |
|---|---|
| Subject matter | Provision of the ClientCollect document-collection service |
| Duration | The term of the Agreement, plus any deletion or return period |
| Nature and purpose | Collecting, storing, organising and managing documents and information that data subjects submit to the Controller through the Service |
| Types of personal data | Identity and contact details; documents and their contents (which may include financial, identity and other information the Controller chooses to collect); messages; and usage data. May include special-category data where the Controller chooses to collect it. |
| Categories of data subjects | The Controller's clients and other individuals from whom the Controller collects information, and the Controller's own personnel |
| Sub-processor | Purpose | Location |
|---|---|---|
| Heroku (Salesforce) | Application hosting | EU (Ireland) |
| Amazon Web Services (AWS) | Cloud storage and infrastructure | EU |
| Anthropic | AI assistant features | United States |
| Resend | Transactional email | EU |
| Stripe | Payment processing | United States |
Transfers to sub-processors located outside the EEA (currently Anthropic and Stripe, in the United States) are made under appropriate safeguards as described in Section 7.