Data Processing Agreement

Effective date: 24 September 2026

This Data Processing Agreement forms part of the MarginNudge Terms of Service when MarginNudge Ltd processes personal data on behalf of a business customer.

1 Parties and status

This Data Processing Agreement (DPA) is between the Customer identified through the MarginNudge account or applicable order form and MarginNudge Ltd, company number 17470390, of 71-75 Shelton Street, Covent Garden, London, WC2H 9JQ, United Kingdom.

The Customer is the controller and MarginNudge is the processor for Customer Personal Data processed to provide the service. Where the Customer acts as a processor for another controller, MarginNudge acts as the Customer’s subprocessor. Each party remains responsible for its own obligations under applicable Data Protection Laws.

2 Definitions and precedence

Customer Personal Data means personal data contained in Customer Data that MarginNudge processes on the Customer’s behalf. Data Protection Laws means the UK GDPR, the Data Protection Act 2018, the Privacy and Electronic Communications Regulations 2003 and any legislation that replaces, supplements or amends them, including applicable provisions of the Data (Use and Access) Act 2025.

Controller, processor, data subject, personal data, processing, special category data and personal data breach have the meanings given by Data Protection Laws. If this DPA conflicts with the Terms on the processing of Customer Personal Data, this DPA prevails for that conflict.

3 Scope and instructions

MarginNudge will process Customer Personal Data only to provide, secure, support and administer the service; generate and deliver customer-requested quote outputs; comply with documented Customer instructions; and meet legal obligations that apply to MarginNudge.

The Terms, the Customer’s configuration and permitted use of the service constitute the Customer’s documented instructions. Additional instructions must be lawful, technically feasible, consistent with the service and agreed in writing. MarginNudge will inform the Customer if, in its reasonable opinion, an instruction infringes Data Protection Laws, unless prohibited from doing so.

4 Customer obligations

  • The Customer must ensure its instructions and processing comply with Data Protection Laws.
  • The Customer must have an appropriate lawful basis and provide required privacy information to relevant individuals.
  • The Customer must collect and submit only information needed for its quote and commercial workflow.
  • The Customer must not submit special category data, criminal offence data, children’s data, payment card numbers, passwords, national insurance numbers or other unnecessary sensitive data.
  • The Customer must configure user access appropriately and keep authorised-user details current.
  • The Customer is responsible for assessing whether the service and its available safeguards are suitable for its intended processing.

5 MarginNudge obligations

  • Process Customer Personal Data only on documented instructions, unless UK law requires otherwise.
  • Ensure that authorised personnel are subject to appropriate confidentiality duties.
  • Implement and maintain appropriate technical and organisational measures described in Schedule 2.
  • Assist the Customer, taking account of the nature of processing and information available, with data subject rights, security, breach obligations, data protection impact assessments and regulator consultations.
  • Maintain records and information reasonably necessary to demonstrate compliance with this DPA.
  • Notify the Customer if MarginNudge can no longer comply with this DPA and take reasonable steps to remedy the issue.
  • Not sell Customer Personal Data or use it for targeted advertising.
  • Not use Customer Personal Data to train artificial intelligence or machine-learning models. The MVP does not use AI.

6 Security

MarginNudge will maintain security appropriate to the risk, taking into account the state of the art, implementation cost and the nature, scope, context and purposes of processing. The current core measures are set out in Schedule 2. MarginNudge may update measures where the overall level of protection is not materially reduced.

7 Personal data breaches

MarginNudge will notify the Customer without undue delay after becoming aware of a confirmed personal data breach affecting Customer Personal Data. The notice will include available information about the nature of the breach, likely consequences, affected data and data subjects, mitigation and a contact point. Information may be provided in phases as it becomes available.

MarginNudge will take reasonable steps to contain, investigate and mitigate the breach. Notification does not constitute an admission of fault or liability. The Customer is responsible for deciding whether to notify a regulator or affected individual, with MarginNudge providing reasonable assistance.

8 Data subject requests

If MarginNudge receives a request relating to Customer Personal Data, it will promptly refer the request to the Customer where the responsible Customer can be identified. MarginNudge will not respond on the Customer’s behalf unless instructed or legally required. The Customer may use available service functionality to access, correct, export or delete relevant data.

9 Subprocessors

The Customer gives general written authorisation for MarginNudge to use the providers listed in the current MarginNudge Subprocessor List. MarginNudge will impose data protection obligations on each subprocessor that are no less protective in substance than the relevant obligations in this DPA, as required by law. MarginNudge remains responsible for the performance of its subprocessors to the extent required by Data Protection Laws.

MarginNudge will provide at least 15 days’ notice before a new subprocessor begins materially processing Customer Personal Data, normally by updating the list and using the notification mechanism offered on that page or by email. The Customer may object during that period on reasonable data protection grounds. The parties will work in good faith to resolve the concern. If no reasonable alternative is available, either party may terminate the affected service without penalty before the new subprocessor begins processing.

10 International transfers

MarginNudge will not make a restricted transfer of Customer Personal Data outside the United Kingdom unless it uses a lawful transfer mechanism and meets applicable UK transfer requirements. Where required, the parties incorporate the UK International Data Transfer Addendum to the EU Standard Contractual Clauses, or another UK-approved mechanism applicable to the transfer. MarginNudge may rely on UK adequacy regulations where available.

The Customer authorises onward transfers by approved subprocessors where they are covered by an appropriate safeguard and the relevant subprocessor contract.

11 Return and deletion

Following termination or cancellation, the Customer will normally have 14 days to access or export available Customer Data. Unless law requires retention, MarginNudge will delete or irreversibly anonymise Customer Personal Data from active systems within 30 days after that access period. Residual encrypted backup copies will be removed through the ordinary backup cycle, targeted within 90 days after active-system deletion, and will not be restored except for disaster recovery or legal purposes.

MarginNudge may retain limited information where required by law or reasonably necessary to establish, exercise or defend legal claims. Any retained Customer Personal Data remains protected by this DPA and is processed only for the retention purpose.

12 Audits and information

On reasonable written request and no more than once in any 12-month period, MarginNudge will provide information reasonably necessary to demonstrate compliance with this DPA, such as relevant policies, provider reports or questionnaire responses. Additional requests may be made after a material breach or where a regulator requires them.

If the information provided is insufficient, the Customer may request a proportionate audit by an independent auditor bound by confidentiality, on at least 30 days’ notice, during normal business hours and without accessing another customer’s information or compromising security. The Customer bears its audit costs unless the audit identifies a material breach by MarginNudge.

13 Liability and duration

The liability provisions in the Terms apply to this DPA to the fullest extent permitted by law. This DPA begins when the Customer accepts the Terms or otherwise starts using the service and continues for as long as MarginNudge processes Customer Personal Data.

14 Governing law

This DPA and any non-contractual obligations arising from it are governed by the laws of England and Wales. The courts of England and Wales have exclusive jurisdiction, subject to any mandatory rights under Data Protection Laws or an applicable transfer mechanism.

Schedule 1 Processing details

ItemDescription
Subject matterProvision of the MarginNudge multi-tenant B2B quote assessment, approval, document generation, email delivery, account and support service.
DurationFor the agreement term and the deletion periods described in section 11.
Nature and purposeCollection, recording, organisation, hosting, retrieval, calculation, display, versioning, access control, PDF generation, customer-confirmed transmission, support, security, backup, export and deletion.
Data subjectsCustomer personnel and authorised users; invited users; the Customer’s clients, prospects, contractors, suppliers and quote recipients; other business contacts included by the Customer.
Personal dataNames, work email addresses, business contact details, roles, user and authentication identifiers, workspace membership, client or prospect identifiers, quote-recipient details, quote and scope content, commercial and role-cost information where linked to an individual, approvals, audit records, usage and security metadata.
Sensitive dataNot intended or permitted. Customers must not submit special category data, criminal offence data, children’s data or unnecessary sensitive identifiers.
FrequencyContinuous or as initiated by authorised users during use of the service.
Controller rightsThe rights and obligations set out in the Terms, this DPA and Data Protection Laws, including lawful instructions, access, correction, export, deletion and audit rights.

Schedule 2 Technical and organisational measures

Control areaMeasures
Access controlVerified email/password or Google authentication; role-based permissions; active workspace membership checks; restricted internal operator access; least privilege.
Tenant separationRow-level security on customer-owned tables, same-tenant checks, private storage paths and cross-tenant access testing.
Encryption and secretsEncrypted network connections; provider-supported encryption at rest; server-side service credentials and webhook secrets; short-lived signed file URLs.
Application integrityServer-side calculations, immutable assessed versions, input hashes, controlled lifecycle transitions and validation against defined rules.
Logging and auditAppend-only audit records for material decisions and operator actions; signed and idempotent Stripe and Resend event handling; security monitoring.
Data minimisationNo storage of full payment-card data; analytics events exclude sensitive quote content and recipient addresses; client-facing outputs use an allowlist.
ResilienceAutosave, backups, recoverable error states, safe retries and controlled restoration procedures.
Development and operationsRestricted production access, separation of client and server responsibilities, dependency and vulnerability management, controlled changes and incident procedures.
PersonnelAccess limited to authorised personnel and contractors with appropriate confidentiality duties and operational need.
DeletionActive-system deletion and backup expiry processes aligned to section 11, subject to legal retention.

Schedule 3 Approved subprocessors

The current approved providers, purposes, processing locations and transfer safeguards are set out in the MarginNudge Subprocessor List published at marginnudge.com/legal/subprocessors. That list is incorporated into this DPA.

Company information

MarginNudge is a trading name of MarginNudge Ltd, a company registered in England and Wales under company number 17470390. Registered office: 71-75 Shelton Street, Covent Garden, London, WC2H 9JQ, United Kingdom. Contact: contact@marginnudge.com.