Skip to content

Data processing agreement

Version 1.0, in force from 16 September 2026.

You do not need to sign this, and you do not need to ask us for it. It applies automatically from the moment you first submit a document, and it forms part of your contract with us. If your firm needs a countersigned copy on headed paper for its own files, write to hello@datanem.com and you will get one.

1. What this covers and who is who

This agreement is between DATANEM LIMITED, registered in England and Wales under number 16870006 at 8 Court View, Clowne, Chesterfield, England, S43 4BU ("we", "us"), registered with the Information Commissioner's Office under reference ZC053711, and the account holder ("you"). It gives effect to Article 28(3) of the UK GDPR.

Where your documents contain personal data, you are the controller and we are the processor. You determine what is extracted and why. We process it only to provide the service. Where more than one person shares an account, the account holder is the controller.

We are a separate controller, not your processor, for your own account and billing records. That is covered by the privacy notice instead.

2. The processing, described as Article 28(3) requires

  • Subject matter: converting documents you submit into structured data.
  • Duration: for as long as your account is open, subject to the deletion periods in clause 8.
  • Nature and purpose: storage, optical character recognition, automated extraction into columns you define, and making the result available to you for export.
  • Types of personal data: whatever appears in the documents you choose to send. Typically names, addresses, contact details, employment and payment details, bank account details and transaction records.
  • Categories of data subject: whoever your documents describe. Typically your clients, their customers and suppliers, and your or their employees.
  • Special category data: the service is not designed for it and we ask you not to send it. If your documents contain it, you are responsible for having an Article 9 condition.

3. What we will and will not do with it

  • We process personal data only on your documented instructions. Your use of the service is that instruction; this agreement and the privacy notice record it.
  • We will not use your documents, or anything extracted from them, for our own purposes. We do not train, fine-tune or evaluate models on them, and we do not sell or share them.
  • If we are ever required by law to process your data otherwise, we will tell you before doing so unless the law forbids us from saying.
  • If we think an instruction of yours breaches data protection law, we will tell you.

4. Confidentiality

Access is restricted to those who need it to run the service. Everyone with access is bound by a duty of confidentiality that survives the end of their involvement. In practice the company is very small, which means the list of people who could access anything is short and known.

5. Sub-processors

You give general written authorisation for us to engage the sub-processors listed on the sub-processors page, which names each one, what it receives and where it processes.

We will give you at least 30 days' notice before adding or replacing one. If you object on reasonable data protection grounds within that period, tell us and we will either propose an alternative or you may terminate the affected part of the service and receive a pro rata refund of anything paid in advance. We impose equivalent obligations on every sub-processor and remain liable to you for what they do.

6. Transfers outside the UK

Some processing happens outside the UK, including within the EEA and, as set out on the sub-processors page, potentially beyond it. Each transfer relies on the UK International Data Transfer Addendum, the EU standard contractual clauses, or the UK-US Data Privacy Framework. The specific mechanism for each provider is named rather than described generically, so you can check it.

7. Security

We take the technical and organisational measures required by Article 32, described concretely on the security page rather than as a list of adjectives. In summary: TLS in transit, encryption at rest, isolation of each account's data, no shared administrative credentials, and no document content in logs.

We will assist you, so far as is reasonable and taking account of the information available to us, with your obligations under Articles 32 to 36, including data protection impact assessments and any consultation with the Information Commissioner.

8. Deletion and return

Documents and extracted data are deleted automatically on the retention clock for your plan: 30 days on Free, 90 on Starter, 180 on Pro and 365 on Max. You can delete anything sooner from within the app, and you can export at any time before deletion.

On termination we delete your content. As the privacy notice explains in full, our database platform retains a restorable history for up to 30 days and our extraction provider retains API inputs for up to 30 days for abuse monitoring, so complete removal from every backing system follows within 30 days rather than instantly. We would rather write that here than promise you something a supplier does not support.

9. Helping you answer the people in your documents

If someone whose data appears in a document you uploaded exercises a right, you answer them, because you are the controller. Deleting the job in the app removes the underlying file. Where you need more than that, write to hello@datanem.com and we will help you locate or extract what you need. If such a person contacts us directly, we will not answer on your behalf; we will tell them to approach you and let you know.

10. Breaches

If we become aware of a personal data breach affecting your data, we will tell you without undue delay, with what we know about what happened, who is affected, the likely consequences and what we are doing about it. We will keep you updated as we learn more, so that you can meet your own 72 hour duty to the Information Commissioner.

11. Audit

We will make available the information needed to demonstrate compliance with Article 28, and will respond to reasonable written questions, including security questionnaires. You may audit once in any twelve month period on 30 days' notice, at your cost, subject to confidentiality and to not disrupting other customers. In most cases written answers and the documents on this site will settle it faster.

12. Liability, law and precedence

Liability under this agreement is subject to the limits in the licence. This agreement is governed by the law of England and Wales, and the courts of England and Wales have exclusive jurisdiction.

If anything in the terms or the licence conflicts with this agreement on the processing of personal data, this agreement wins.

Datanem is a product of DATANEM LIMITED, a company registered in England and Wales, number 16870006. Registered office: 8 Court View, Clowne, Chesterfield, England, S43 4BU. Registered with the Information Commissioner's Office, reference ZC053711.