Legal · Data Processing Addendum

Already signed,
already in force.

This addendum is incorporated by reference into every paid plan, so there is nothing to counter-sign before you go live. A wet-signed copy is available if your process needs one.

Effective
1 June 2026
Last updated
28 August 2026
Contracting entity
Spotit Ltd

1Incorporation#

This Data Processing Addendum (“DPA”) forms part of the Terms of Service or of any Enterprise MSA between Spotit Ltd (“Processor”) and the customer (“Controller”). It takes effect on the day the agreement does, without further signature.

If your procurement process requires an executed copy naming your entity, email legal@spotit.ai with the entity name and address and you will get one back, signed, usually the same day. We do not charge for it and we do not route it through a sales call.

2Definitions#

“GDPR” means Regulation (EU) 2016/679, and where it applies, the UK GDPR as incorporated by the Data Protection Act 2018. “Controller”, “Processor”, “Data Subject”, “Personal Data”, “Processing” and “Supervisory Authority” carry their GDPR meanings. “SCCs” means the Standard Contractual Clauses annexed to Commission Implementing Decision (EU) 2021/914. “Customer Personal Data” means personal data contained in Customer Content that we process on your behalf.

3Roles of the parties#

For Customer Content — the records you send to the API, your account users, and the material in your support tickets — you are the Controller and we are the Processor.

For register data obtained from public sources, and for our own business records about your account, we are an independent Controller. That processing is described in the Privacy Policy and is outside the scope of this DPA. Neither party is a joint controller with the other.

In plain terms

What you send us, we process for you. What we ingest from a register, we control ourselves. Those are two contracts in one relationship and this document only governs the first.

4Processing instructions#

We process Customer Personal Data only on your documented instructions, which consist of this DPA, the agreement, the API documentation, and any configuration you set in the console — including region pinning and the input-retention setting.

We will tell you if, in our opinion, an instruction infringes the GDPR, and we may suspend that instruction until it is resolved. If we are required by EU or member-state law to process beyond your instructions, we will tell you before doing so unless that law prohibits it.

We will not sell Customer Personal Data, use it for our own marketing, use it to train machine learning models, or merge it into the public entity graph.

5Annex A · Details of processing#

Subject matterProvision of entity resolution, entity reference data, change monitoring and related APIs
DurationThe term of the agreement, plus the deletion window in clause 13
Nature and purposeReceiving query inputs, matching them against the entity graph, returning results, metering usage, delivering webhooks, and supporting you
Categories of data subjectYour personnel who use the console; company officers, contacts and sole traders appearing in records you submit
Categories of personal dataBusiness contact details, company and trading names, addresses, registration identifiers, and any personal data you choose to include in a query input or sample file
Special categoriesNone. Do not send them; the API has no field that needs them
FrequencyContinuous, on your API calls
Retention30 days for query inputs by default, configurable to zero on Business and Enterprise; account data for the life of the account

6Confidentiality of personnel#

Access to Customer Personal Data is limited to personnel who need it to deliver or support the service. Everyone with such access is bound by a written confidentiality obligation that survives their employment, has completed data protection training in the last 12 months, and holds access granted under least privilege and reviewed quarterly.

Production access requires SSO with hardware-backed MFA, is time-boxed, and is logged to an append-only audit trail that we retain for 12 months.

7Annex B · Technical and organisational measures#

We maintain measures appropriate to the risk under Article 32. The current set is listed here; we may change a specific control provided the level of protection does not fall.

  • Encryption. TLS 1.3 in transit with HSTS and modern cipher suites only; AES-256 at rest for databases, object storage and backups; keys managed in a hosted HSM with annual rotation.
  • Segregation. Customer content is logically separated and keyed by account; production is isolated from staging by account boundary, not by naming convention.
  • Access control. SSO/SAML and SCIM for customers; least privilege internally; scoped, revocable API keys; quarterly access reviews.
  • Redaction. Query inputs are excluded from logs, traces and error reports. Observability records the request ID and the input’s shape, never its content.
  • Resilience. Multi-AZ deployment, point-in-time recovery to any minute in the last 7 days, backups tested quarterly by restoring them, RPO 5 minutes and RTO 1 hour.
  • Testing. Independent penetration testing twice a year, continuous dependency scanning, static analysis in CI, and a bug bounty for anything that reaches production.
  • Governance. ISO 27001 certification and an annual SOC 2 Type II report, both covering ingest, API and support. Reports are available under NDA.
  • Vendor management. Every sub-processor is assessed before onboarding and reviewed annually against the same control set.

8Sub-processors#

You give general authorisation for us to engage sub-processors. The complete current list, with purpose and hosting region for each, is at spotit.ai/legal/sub-processors.

We give at least 30 days notice before adding or replacing one. Subscribe on that page and the notice arrives by email. You may object on reasonable data protection grounds within the notice period; we will work with you to find an alternative, and if we cannot, you may terminate the affected part of the service and receive a refund of prepaid, unused fees.

Each sub-processor is bound by written terms no less protective than this DPA, and we remain fully liable to you for their performance.

9Assistance to the Controller#

Taking into account the nature of the processing, we will assist you with:

  1. Data subject requests. The console and API let you find, export and delete records yourself. If a request reaches us directly we will not answer it on your behalf; we will forward it to you within 5 working days and help you respond.
  2. Article 32 security, by maintaining the measures in Annex B and evidencing them.
  3. Articles 35 and 36, data protection impact assessments and prior consultation, by providing the information reasonably available to us. A pre-written DPIA pack covering the service is available on request.

Assistance is included in your fees. We do not charge for a DPIA pack or for answering a security questionnaire.

10Personal data breach#

We will notify you without undue delay, and in any case within 48 hours of becoming aware of a personal data breach affecting Customer Personal Data. The first notice will describe the nature of the breach, the categories and approximate number of records affected, the likely consequences, and the measures taken or proposed.

Where the full picture is not yet available, we will send what we have and follow up in phases rather than wait. We will not ask you to keep a breach confidential, and we will not require your approval before notifying a supervisory authority of our own obligations.

11International transfers and SCCs#

EU-pinned accounts are processed entirely within the EU. Where a transfer to a third country occurs — because you pinned a key outside the EU, or because a support sub-processor accesses data from the United States — it is made under the SCCs, which are incorporated into this DPA by reference and completed as follows.

  • Module Two (controller to processor) applies where you are a controller; Module Three (processor to processor) where you are yourself a processor.
  • Clause 7, the docking clause, applies.
  • Clause 9, option 2, general written authorisation, with the notice period in clause 8 above.
  • Clause 11, the optional independent dispute resolution body, does not apply.
  • Clause 17, governing law: Ireland. Clause 18(b), forum: the courts of Ireland.
  • Annex I is populated by Annex A above; Annex II by Annex B; Annex III by the sub-processor page.
  • For UK transfers, the UK International Data Transfer Addendum version B1.0 applies to the SCCs, with tables completed to match.

Our transfer impact assessment, including our record of government access requests — which currently stands at zero — is available on request.

12Audit#

On request, and no more than once in any 12 months, we will provide our current SOC 2 Type II report, ISO 27001 certificate and Statement of Applicability, the summary of our latest penetration test, and a completed security questionnaire. For most customers these answer the audit right in full.

Where they do not, you may audit us in person or through an independent auditor who is not our competitor, on 30 days’ notice, during business hours, subject to confidentiality, and without access to another customer’s data. You bear the cost unless the audit finds a material breach of this DPA, in which case we do. A supervisory authority exercising its own powers is not subject to these limits.

13Return and deletion#

You can export your data through the API at any time during the term. On termination we delete Customer Personal Data from production within 30 days and from backups within a further 35 days as they roll off, unless EU or member-state law requires retention — in which case we tell you what and why.

Written confirmation of deletion is provided on request at no charge. Entity records you resolved during the term and stored in your own systems remain yours under clause 3 of the terms.

14Liability#

Each party’s liability under this DPA is subject to the limitations and exclusions in the agreement. Nothing in this DPA limits a data subject’s rights under the GDPR or a supervisory authority’s powers.

15Signature#

This DPA is in force from the effective date of your agreement, without signature. If you need an executed copy on your own paper, or a copy naming a specific group entity, write to legal@spotit.ai.

Spotit Ltd · 14 Hanover Quay, Grand Canal Dock, Dublin 2, D02 XY88, Ireland · Registered in Ireland, company no. 742118

Something here that does not work for you?

Redlines on the self-serve terms are read, not filed. Send them and you will get an answer from someone who can change the document, usually inside two working days.

Spotit Ltd · Registered in Ireland, company no. 742118 · 14 Hanover Quay, Grand Canal Dock, Dublin 2, D02 XY88, Ireland · VAT IE4218806T