data processing agreement
Data Processing Agreement
George Automation — version 1, 18 September 2026
This Data Processing Agreement ("DPA") forms part of the Terms of Service between John Patrick George, trading as George Automation ("George", "we") and the client identified in the George account ("you"). It applies whenever we process personal data on your behalf in providing a service, and it is written to meet Article 28 of the UK GDPR. If it conflicts with the Terms of Service on a data protection matter, this DPA governs.
1. Roles and scope
1.1 For personal data you bring to a service — your customers, contacts, prospects, staff or anyone else whose data we handle to do the work — you are the controller and we are the processor.
1.2 For data about you and your users that we hold to run our own business (account, billing, correspondence), we are the controller and our Privacy Policy applies. This DPA does not.
2. Details of the processing
| Subject matter | The personal data you provide or connect to a George service |
|---|---|
| Duration | The term of the relevant service, plus the 30-day export period in the Terms, plus any period the law requires us to keep records |
| Nature and purpose | Setting up, operating and supporting the service you have bought, as described on its product page and in any written quote — for example sending order notifications, drafting and publishing content, running outreach sequences, generating reports |
| Types of personal data | Typically: names, email addresses, phone numbers, postal addresses, order and purchase history, communications, social-media handles, job titles and company details. Not special-category data unless you tell us in writing and we agree |
| Categories of data subject | Your customers, prospects, subscribers, followers, suppliers and staff, as relevant to the service |
3. Our obligations as processor
We will:
3.1 process the personal data only on your documented instructions — which are the Terms, the product description, your quote, your onboarding answers, and instructions you give us in the portal or by email — unless the law requires otherwise, in which case we will tell you before processing unless the law forbids it;
3.2 tell you immediately if we think an instruction breaks data protection law;
3.3 make sure anyone we authorise to process the data (including subcontractors) is bound by confidentiality;
3.4 put in place appropriate technical and organisational security measures for the risk, including at least: encryption in transit; per-client isolation of data enforced at the database level; role-based access with strong authentication; secrets held in encrypted configuration; logging of access to production systems; and regular review of these measures;
3.5 help you respond to requests from individuals exercising their rights (access, erasure, portability and the others), by forwarding any request we receive to you within five working days and providing the data or actions you need;
3.6 help you meet your obligations on security, breach notification, data protection impact assessments and prior consultation with the ICO, taking into account the nature of the processing and the information available to us;
3.7 notify you without undue delay, and in any event within 48 hours of becoming aware of a personal data breach affecting your data, with what we know about its nature, the data and individuals affected, the likely consequences and the steps we are taking;
3.8 at the end of the service, delete or return the personal data at your choice — return is available for 30 days on request, after which we delete, unless the law requires us to keep it;
3.9 give you the information you reasonably need to show that we comply with Article 28, and allow and contribute to audits you conduct or mandate — on 30 days' notice, no more than once a year unless a breach or a regulator requires otherwise, during working hours, and subject to confidentiality; where a written report or a recognised certification answers the question, we may provide that instead of on-site access.
4. Sub-processors
4.1 You give us general authorisation to use the sub-processors listed in section 7, and others we add in future.
4.2 We will give you at least 30 days' notice by email before adding or replacing a sub-processor that will process your personal data. If you have a reasonable, data-protection-related objection, tell us within that period and we will work with you to resolve it; if we can't, you may end the affected service on written notice and we will refund any pre-paid amount for the period after the end date.
4.3 We will impose on each sub-processor written obligations no less protective than this DPA, and we remain responsible to you for their performance.
5. International transfers
5.1 We will not transfer your personal data outside the UK except to sub-processors listed in section 7 or added under section 4, and only where the transfer is covered by a valid mechanism: UK adequacy regulations, the UK Extension to the EU-US Data Privacy Framework for a certified recipient, or the International Data Transfer Agreement / UK Addendum to the EU Standard Contractual Clauses.
5.2 On request we will tell you which mechanism applies to each sub-processor.
6. Your obligations as controller
6.1 You are responsible for having a lawful basis for the processing, for the accuracy of the data, for providing privacy information to the individuals concerned, and for your instructions to us being lawful — including, where a service sends marketing messages, for compliance with the Privacy and Electronic Communications Regulations.
6.2 You will not provide us with special-category data, criminal-offence data or data about children without agreeing it with us in writing first.
7. Sub-processors
| Sub-processor | Purpose | Location |
|---|---|---|
| Supabase, Inc. | Database and authentication hosting | European Union (Ireland, AWS eu-west-1) |
| Vercel, Inc. | Application hosting and server logs | United States (DPF-certified) |
| Stripe Payments UK Ltd / Stripe, LLC | Payment processing (only where the service involves taking payments) | United Kingdom, EU, United States (DPF-certified) |
| Resend, Inc. (Amazon Web Services EMEA SARL) | Transactional email sending | EU (Ireland) |
| Microsoft Ireland Operations Ltd | Mailbox | United States and EU (DPF-certified) |
| Third-party AI model providers | Only for products whose page names them; the current list is at georgeautomation.com/legal/dpa | None currently used |
| Subcontractors for creative production | Only for video and creative products, under confidentiality | United Kingdom unless stated |
The current list is always published at georgeautomation.com/legal/dpa.
8. Liability and general
8.1 The liability caps and exclusions in the Terms of Service apply to this DPA, except that nothing in them limits either party's liability for a regulator's fine to the extent the law says it cannot be limited.
8.2 This DPA is governed by the law of England and Wales and lasts for as long as we process personal data on your behalf.
Drafted for George Automation against UK GDPR Article 28 as at September 2026. Not legal advice.
