Data Processing Agreement (template)
Last updated: 22 July 2026. This DPA forms part of the service agreement between the customer identified in the applicable order (the "Controller") and Liam Cordrey, NIF Y7966498W, Andasol Business Center, Avenida Andasol, 29604 Marbella, Málaga, Spain (the "Processor"), and reflects Article 28 GDPR and Spanish Organic Law 3/2018 (LOPDGDD). It is incorporated by reference into every early-access agreement; a countersigned copy is available on request.
1. Subject matter, duration, nature and purpose
The Processor operates the Dispatch service — source monitoring, knowledge-base building, content drafting and an editorial portal — on behalf of the Controller for the duration of the service agreement. Processing consists of hosting, storage, transmission, automated analysis and drafting, and display to the Controller's authorised users.
2. Categories of data and data subjects
| Data subjects | Personal data |
|---|---|
| Controller's authorised users | Name, business email, login identifiers, attributed editorial actions (audit log) |
| Controller's audience/leads | Name, email, company/role and message content submitted through forms on the Controller's own properties |
| Individuals appearing in monitored public sources | Identifying information as published in those public sources (e.g. names of podcast hosts, article authors) |
No special-category data is required by the service; the Controller agrees not to direct such data into it.
3. Obligations of the Processor
The Processor shall: (a) process personal data only on the Controller's documented instructions, including as configured by the Controller in the portal; (b) ensure persons authorised to process the data are bound by confidentiality; (c) implement the technical and organisational measures in §6; (d) respect the subprocessor conditions in §5; (e) taking into account the nature of the processing, assist the Controller with data-subject requests and with articles 32–36 GDPR; (f) at the Controller's choice, return (export) and/or delete all personal data at the end of the service, deleting within 30 days unless law requires retention; (g) make available the information necessary to demonstrate compliance and allow and contribute to audits, on reasonable notice and no more than once per year unless a breach or supervisory authority requires otherwise; (h) inform the Controller immediately if an instruction, in its opinion, infringes data-protection law.
4. Obligations of the Controller
The Controller warrants it has a lawful basis for the personal data it directs into the service, is responsible for its own privacy notices (towards authorised users, audiences and leads), and will keep its list of authorised users current.
5. Subprocessors
The Controller grants general written authorisation to the subprocessors listed at /legal/subprocessors. The Processor will give at least 14 days' notice (by email) before adding or replacing a subprocessor, during which the Controller may object on reasonable data-protection grounds; an unresolved objection entitles the Controller to terminate the affected service without penalty. The Processor imposes data-protection obligations on each subprocessor equivalent to this DPA and remains fully liable for their performance.
6. Security measures (art. 32)
TLS on all connections; access to customer instances restricted to nominated identities via authenticated gateways; per-customer isolation of configuration, data directories and credentials; attribution logging of editorial actions; encrypted backups; EU hosting; the principle that AI providers are used via business APIs that do not train on submitted data; prompt patching of the underlying hosts; secrets held outside version control.
7. Personal-data breaches
The Processor shall notify the Controller without undue delay after becoming aware of a personal-data breach affecting the Controller's data, providing the information reasonably required for the Controller's own art. 33/34 obligations, and shall document breaches and remediation.
8. International transfers
Data is hosted in the EU. Where a subprocessor processes data outside the EEA, transfers rely on an adequacy decision (including the EU–US Data Privacy Framework where certified) or Standard Contractual Clauses, as identified in the subprocessor list.
9. Liability and order of precedence
Liability under this DPA is subject to the limitations in the Terms of Service, except where GDPR provides otherwise. In case of conflict between this DPA and the Terms, this DPA prevails for data-protection matters.