Legal

Data Processing Agreement

Last updated: 30 July 2026

This Data Processing Agreement ("DPA") forms part of the Terms of Service (the "Agreement") between the Customer ("Controller", "you") and Gibney Technology Enterprises Limited ("ClientCollect", "Processor", "we") and applies to our processing of personal data on your behalf when you use the Service. Where this DPA conflicts with the Agreement on data-protection matters, this DPA prevails.

1. Definitions

Terms such as "personal data", "processing", "controller", "processor", "data subject", "personal data breach" and "supervisory authority" have the meanings given in the EU General Data Protection Regulation (Regulation (EU) 2016/679, "GDPR"). "Data Protection Law" means the GDPR and applicable implementing laws.

2. Roles of the parties

For personal data that you and your clients submit into the Service ("Customer Data"), you are the controller and ClientCollect is the processor. You are responsible for the lawfulness of your instructions and for having a lawful basis for the processing. Personal data that ClientCollect controls — for example, your account details — is governed by our Privacy Policy, not this DPA.

3. Processing on documented instructions

We process Customer Data only on your documented instructions — including the Agreement, your configuration and use of the Service, and any written instructions you give — except where required by law, in which case we will inform you unless the law prohibits it. If we believe an instruction infringes Data Protection Law, we will inform you.

4. Confidentiality

We ensure that personnel authorised to process Customer Data are bound by appropriate obligations of confidentiality.

5. Security (Article 32)

We implement appropriate technical and organisational measures to ensure a level of security appropriate to the risk, as summarised in Annex 2.

6. Sub-processors

You provide general authorisation for us to engage sub-processors to process Customer Data. Current sub-processors are listed in Annex 3. We impose data-protection obligations on each sub-processor no less protective than those in this DPA, and we remain responsible for their performance. We will give you advance notice of any intended addition or replacement of a sub-processor and a reasonable opportunity to object on reasonable data-protection grounds.

7. International transfers

Where processing involves transferring Customer Data outside the EEA, we rely on an adequacy decision or appropriate safeguards, including the European Commission's Standard Contractual Clauses, which are incorporated by reference where applicable.

8. Assistance with data-subject rights

Taking into account the nature of the processing, we assist you by appropriate technical and organisational measures, insofar as possible, to respond to requests from data subjects exercising their rights under the GDPR. Where a data subject contacts us directly about Customer Data, we will refer them to you.

9. Assistance with security, breaches and impact assessments (Articles 32–36)

We assist you in ensuring compliance with your obligations relating to security, breach notification, data-protection impact assessments and prior consultation, taking into account the nature of processing and the information available to us.

10. Personal data breach

We notify you without undue delay after becoming aware of a personal data breach affecting Customer Data, and provide the information reasonably available to us to help you meet your own notification obligations.

11. Deletion or return

On termination of the Service, we will, at your choice, delete or return Customer Data and delete existing copies, unless law requires storage. Data held in backups is deleted in line with our backup cycle.

12. Audits

We make available to you the information necessary to demonstrate compliance with Article 28 and allow for and contribute to audits, including inspections, conducted by you or an auditor you mandate, subject to reasonable confidentiality, security, notice and frequency conditions.

13. Liability

Each party's liability under this DPA is subject to the limitations of liability set out in the Agreement.


Annex 1 — Details of the processing

Item Detail
Subject matter Provision of the ClientCollect document-collection service
Duration The term of the Agreement, plus any deletion or return period
Nature and purpose Collecting, storing, organising and managing documents and information that data subjects submit to the Controller through the Service
Types of personal data Identity and contact details; documents and their contents (which may include financial, identity and other information the Controller chooses to collect); messages; and usage data. May include special-category data where the Controller chooses to collect it.
Categories of data subjects The Controller's clients and other individuals from whom the Controller collects information, and the Controller's own personnel

Annex 2 — Technical and organisational measures (Article 32)

  • Encryption of personal data in transit (TLS) and at rest
  • Role-based access controls and least-privilege access; passwordless authentication
  • Timestamped audit logging of key actions
  • Segregation of Customer Data by account
  • Regular automated backups and recovery procedures
  • Secure software development and dependency management
  • Hosting with a reputable infrastructure provider offering physical and network security

Annex 3 — Sub-processors

Sub-processor Purpose Location
Heroku (Salesforce) Application hosting EU (Ireland)
Amazon Web Services (AWS) Cloud storage and infrastructure EU
Anthropic AI assistant features United States
Resend Transactional email EU
Stripe Payment processing United States

Transfers to sub-processors located outside the EEA (currently Anthropic and Stripe, in the United States) are made under appropriate safeguards as described in Section 7.