Data Processing Addendum

Last updated: August 2026

This Data Processing Addendum (the “DPA”) forms part of the Terms of Service between Progressio AI Limited (“Progressio.ai”, “we”, “us”) and the Customer.

This DPA applies to the extent that Progressio.ai processes Personal Data on behalf of the Customer in connection with the Service.

Capitalised terms not defined in this DPA have the meanings given to them in the Terms.

For the purposes of this DPA:

“Applicable Data Protection Law” means the UK GDPR, the Data Protection Act 2018 and, where applicable to the relevant processing, the EU GDPR and other applicable laws governing the processing of Personal Data.

“Controller”, “Processor”, “Data Subject”, “Personal Data”, “Personal Data Breach”, “processing” and “process” have the meanings given to them under Applicable Data Protection Law.

“Sub-processor” means a third party engaged by Progressio.ai to process Personal Data on behalf of the Customer in connection with the Service.

1. Scope

This DPA applies only to the extent that Customer Data processed through the Service contains Personal Data and Progressio.ai processes that Personal Data on behalf of the Customer.

It does not apply to processing for which Progressio.ai acts as an independent Controller, including Personal Data processed for its own account administration, billing, security, legal or regulatory purposes. Such processing is governed by Progressio.ai’s Privacy Notice and Applicable Data Protection Law.

The subject matter, duration, nature and purpose of the processing, categories of Personal Data and categories of Data Subjects are set out in Schedule 1.

2. Roles of the parties

For processing subject to this DPA, the Customer is the Controller and Progressio.ai is the Processor.

The Customer is responsible for ensuring that its instructions to Progressio.ai comply with Applicable Data Protection Law and that it has an appropriate lawful basis for Personal Data made available to the Service.

Progressio.ai will process Personal Data only on the Customer’s documented instructions, including as set out in the Terms, the applicable Order Form, this DPA and the Customer’s configuration and use of the Service, unless Progressio.ai is required to process Personal Data by applicable law.

Where legally permitted, Progressio.ai will inform the Customer of such a legal requirement before carrying out the processing.

Progressio.ai will promptly inform the Customer if, in its reasonable opinion, a documented instruction infringes Applicable Data Protection Law.

3. Processing obligations

Progressio.ai will process Personal Data only on the Customer’s documented instructions and only to the extent necessary to provide the Service, unless otherwise required by applicable law.

The Customer’s documented instructions include the Terms, the applicable Order Form, this DPA, the Customer’s configuration and use of the Service, and any additional written instructions agreed between the parties.

Any additional instruction must be consistent with the scope and functionality of the Service and Applicable Data Protection Law. Progressio.ai is not required to comply with an instruction that would require a material change to the Service, impose disproportionate cost or operational burden, or require Progressio.ai to process Personal Data for a purpose outside the agreed scope of the Service, unless separately agreed in writing.

Where Progressio.ai is required by applicable law to process Personal Data otherwise than on the Customer’s documented instructions, Progressio.ai will inform the Customer of that legal requirement before carrying out the processing, unless the law prohibits such notification.

Progressio.ai may suspend affected processing where it reasonably considers that a Customer instruction infringes Applicable Data Protection Law while the parties seek to resolve the issue.

4. Confidentiality

Progressio.ai will ensure that any person authorised to process Personal Data is subject to a duty of confidentiality in respect of that Personal Data, whether by contract, professional obligation or applicable law.

Progressio.ai will limit access to Personal Data to personnel who require access for the purpose of providing, supporting or securing the Service or otherwise complying with Progressio.ai’s obligations under this DPA.

The confidentiality obligations in this section are in addition to the confidentiality obligations set out in the Terms

5. Security

Progressio.ai will implement and maintain appropriate technical and organisational measures designed to protect Personal Data against accidental or unlawful destruction, loss, alteration, unauthorised disclosure or access, taking into account the state of the art, costs of implementation, nature, scope, context and purposes of processing, and risks to the rights and freedoms of Data Subjects.

Those measures will include, as appropriate to the relevant processing and risk:

  • measures to protect the confidentiality, integrity, availability and resilience of systems and services used to process Personal Data;
  • access controls designed to restrict access to Personal Data to authorised persons;
  • appropriate protection of Personal Data in transit and at rest;
  • measures to maintain and restore the availability of systems and Personal Data following a security incident; and
  • processes for assessing and reviewing the effectiveness of security measures.

The technical and organisational measures currently maintained by Progressio.ai are described in Schedule 2.

Progressio.ai may update those measures from time to time, provided that the overall level of protection afforded to Personal Data is not materially reduced.

The Customer is responsible for using the Service in accordance with its own security and data-protection obligations and for appropriately managing access by its authorised users.

6. Personal Data Breaches

Progressio.ai will notify the Customer without undue delay after becoming aware of a Personal Data Breach affecting Personal Data processed under this DPA.

To the extent reasonably available to Progressio.ai, the notification will include information sufficient to assist the Customer in meeting its obligations under Applicable Data Protection Law, including:

  • the nature of the Personal Data Breach;
  • the categories and approximate number of affected Data Subjects and Personal Data records, where known;
  • the likely consequences of the Personal Data Breach; and
  • the measures taken or proposed to address the Personal Data Breach and mitigate its possible adverse effects.

Where all relevant information is not available at the time of initial notification, Progressio.ai may provide further information in phases without undue delay as it becomes available.

Progressio.ai will take reasonable steps to contain, investigate and mitigate the Personal Data Breach and will reasonably cooperate with the Customer in relation to its assessment of and response to the Personal Data Breach.

The Customer is responsible for determining whether notification to a supervisory authority or affected Data Subjects is required and for making any such notification, unless applicable law requires Progressio.ai to do so directly.

7. Data Subject Requests

Taking into account the nature of the processing, Progressio.ai will provide the Customer with reasonable assistance, through appropriate technical and organisational measures where reasonably possible, to enable the Customer to respond to requests from Data Subjects exercising their rights under Applicable Data Protection Law.

If Progressio.ai receives a request directly from a Data Subject relating to Personal Data processed on behalf of the Customer, Progressio.ai will, where reasonably able to identify the relevant Customer, promptly notify the Customer and will not respond to the request except on the Customer’s documented instructions or where required by applicable law.

The Customer is responsible for responding to Data Subject requests and determining whether and how the relevant rights apply.

Progressio.ai’s assistance will be limited to Personal Data and information reasonably available to it in connection with the Service. Progressio.ai is not required to recreate, recover or retain Customer Data that has been deleted in accordance with the Terms, this DPA or the Customer’s instructions.

8. DPIAs and regulatory assistance

Taking into account the nature of the processing and information available to Progressio.ai, Progressio.ai will provide the Customer with reasonable assistance in meeting its obligations under Applicable Data Protection Law in relation to:

  • security of processing;
  • assessment and notification of Personal Data Breaches;
  • data protection impact assessments; and
  • prior consultation with a supervisory authority where required.

Any assistance will be limited to matters relating to Progressio.ai’s processing of Personal Data on behalf of the Customer and information reasonably available to Progressio.ai.

Progressio.ai is not responsible for carrying out the Customer’s data protection impact assessment, determining whether the Customer’s processing requires a data protection impact assessment or prior consultation, or otherwise assessing the lawfulness of the Customer’s processing activities.

Where the Customer requests assistance materially beyond that reasonably required for Progressio.ai to comply with its obligations as Processor under Applicable Data Protection Law, the parties may agree the scope of the additional assistance and any applicable charges in writing.

9. Sub-processors

The Customer gives Progressio.ai general written authorisation to engage Sub-processors to process Personal Data on its behalf in connection with the Service.

Progressio.ai will maintain a current list of Sub-processors that may process Personal Data under this DPA and will make that list available to the Customer.

Progressio.ai will give the Customer written notice of any intended addition or replacement of a Sub-processor that will process Personal Data. The notice will identify the proposed Sub-processor and the processing it will perform and specify a reasonable period within which the Customer may object.

The Customer may object to a proposed Sub-processor on reasonable grounds relating to the protection of Personal Data. If the Customer objects within the specified period, the parties will work in good faith to address the Customer’s concerns.

Where the parties cannot reasonably resolve the objection, Progressio.ai may, where reasonably practicable:

  • provide the affected part of the Service without use of that Sub-processor; or
  • offer an alternative configuration that does not require that Sub-processor.

If neither option is reasonably practicable, either party may terminate the affected part of the Service on written notice, and Progressio.ai will refund any prepaid fees relating to the unused portion of the terminated Service.

Before permitting a Sub-processor to process Personal Data, Progressio.ai will enter into a written agreement imposing the data protection obligations required by Applicable Data Protection Law in respect of the processing performed by that Sub-processor.

Progressio.ai remains responsible to the Customer for the performance of the data protection obligations of its Sub-processors.

10. International transfers

Progressio.ai’s primary hosting environment for the Service is located in Europe.

Progressio.ai will not make a transfer of Personal Data that is restricted under Applicable Data Protection Law unless that transfer is permitted under Applicable Data Protection Law.

Where a restricted transfer requires a transfer mechanism, Progressio.ai will ensure that an appropriate mechanism is in place, including, as applicable:

  • an applicable adequacy decision or adequacy regulation;
  • the European Commission’s Standard Contractual Clauses;
  • the UK International Data Transfer Agreement or UK Addendum to the European Commission’s Standard Contractual Clauses; or
  • another lawful transfer mechanism recognised under Applicable Data Protection Law.

Where required, Progressio.ai will carry out or support any transfer risk assessment, data protection test or other assessment required by Applicable Data Protection Law.

Progressio.ai will require Sub-processors making restricted transfers of Personal Data to implement appropriate transfer mechanisms in accordance with Applicable Data Protection Law.

Information about the locations in which Sub-processors process Personal Data and applicable transfer mechanisms will be made available to the Customer on request.

11. Return and deletion of Personal Data

On expiry or termination of the Customer’s subscription, or earlier on the Customer’s documented instruction where applicable, Progressio.ai will, at the Customer’s choice, delete or return Personal Data processed on behalf of the Customer, unless applicable law requires its continued retention.

This obligation applies to Personal Data contained in Customer Data retained by Progressio.ai at that time, including specified excerpts or source material retained at the Customer’s request.

Where Personal Data is contained in retained Audit Results, Progressio.ai will return or delete that Personal Data, including by deleting the relevant Audit Result where necessary.

Personal Data that has already been deleted in accordance with the Terms or this DPA is not required to be recreated or recovered.

Where immediate deletion from backup or archival systems is not technically practicable, Progressio.ai may retain the relevant Personal Data until it is deleted in accordance with its normal backup or deletion cycle, provided that the Personal Data is not restored to active use except where necessary for disaster recovery or as required by law and remains protected in accordance with this DPA.

On the Customer’s reasonable request, Progressio.ai will confirm completion of deletion required under this section.

12. Information, audits and inspections

Progressio.ai will make available to the Customer information reasonably necessary to demonstrate compliance with its obligations under this DPA and Applicable Data Protection Law.

Where reasonably sufficient to demonstrate compliance, Progressio.ai may provide relevant policies, security documentation, responses to due diligence questionnaires, audit reports, certifications or other appropriate evidence.

Where the Customer reasonably requires further verification, Progressio.ai will allow for and contribute to an audit or inspection carried out by the Customer or an independent auditor appointed by the Customer, subject to the following conditions:

  • the audit must relate to Progressio.ai’s processing of Personal Data on behalf of that Customer and compliance with this DPA;
  • the Customer must give reasonable advance written notice, unless a Personal Data Breach, regulatory requirement or other urgent circumstance reasonably requires shorter notice;
  • audits must be conducted during normal business hours and in a manner that does not unreasonably interfere with Progressio.ai’s business or the security or confidentiality of the Service or other customers;
  • an independent auditor must be subject to appropriate confidentiality obligations and must not be a competitor of Progressio.ai;
  • the audit must not require Progressio.ai to disclose information relating to other customers, information that would compromise the security of the Service, legally privileged information, or Progressio.ai source code, models, algorithms or other proprietary technology, except to the extent disclosure is required by applicable law; and
  • the parties will use reasonable efforts to avoid unnecessary duplication of audits or requests for information.

Progressio.ai will promptly address any material non-compliance with this DPA identified through an audit or inspection.

Where an audit or request for assistance goes materially beyond what is reasonably necessary to demonstrate Progressio.ai’s compliance with this DPA, the parties may agree reasonable charges reflecting the additional work required.

13. Liability and relationship with the Terms

The liability of Progressio.ai and the Customer arising under or in connection with this DPA is subject to the limitations and exclusions of liability set out in the Terms.

Nothing in this DPA excludes or limits any liability that cannot lawfully be excluded or limited, or affects the rights of Data Subjects or powers of a supervisory authority under Applicable Data Protection Law.

14. General

This DPA forms part of the Terms and takes effect when Progressio.ai begins processing Personal Data on behalf of the Customer in connection with the Service. It remains in effect for as long as Progressio.ai processes Personal Data on behalf of the Customer.

If there is a conflict between this DPA and the Terms in relation to the processing of Personal Data, this DPA will prevail.

If an applicable international data transfer mechanism incorporated under Section 10 conflicts with this DPA, that transfer mechanism will prevail to the extent required by Applicable Data Protection Law.

If a change in Applicable Data Protection Law requires an amendment to this DPA, the parties will cooperate in good faith to make any amendment reasonably necessary to maintain compliance.

Progressio.ai may update this DPA to reflect changes in Applicable Data Protection Law or the Service, provided that the update does not materially reduce the protection afforded to Personal Data, and will notify the Customer of any material change.

Expiry or termination of this DPA does not affect any provision which, by its nature or purpose, is intended to continue, including obligations relating to confidentiality, return or deletion of Personal Data, liability and audits relating to processing carried out while this DPA was in effect.

The governing law and jurisdiction provisions of the Terms apply to this DPA.

Schedule 1: Details of Processing

ItemDescription
Subject matterTo the extent that Customer Data contains Personal Data, processing of that Personal Data as an incidental part of Progressio.ai’s processing of Customer Data to provide the Service.
DurationFor the period necessary to perform the relevant processing through the Service and, where applicable, for the duration of the Customer’s subscription. Underlying Customer Data is not normally retained after the relevant processing is complete. Audit Results may be retained in accordance with the Terms. Where the Customer expressly requests that specified excerpts or source material be retained, those materials may be retained for the agreed period.
Nature of processingReceiving, accessing, transmitting, temporarily storing, parsing, analysing, extracting, classifying, organising and otherwise processing Customer Data in order to provide the Service. Where Customer Data incidentally contains Personal Data, that Personal Data may be subject to the same processing operations.
PurposeProgressio.ai does not process Personal Data for a separate or independent purpose on behalf of the Customer. Any Personal Data processing is incidental to providing the Service, including identifying and assessing evidence within Customer Data against defined requirements and generating Audit Results.
Types of Personal DataThe Service does not ordinarily require Personal Data. Where Customer Data incidentally contains Personal Data, this may include names, job titles, business contact details, organisational roles or other information identifying individuals referred to in the Customer’s documentation or records.
Special category and criminal offence dataThe Service is not designed or intended for processing special category Personal Data or criminal offence data, and such data is not ordinarily required to use the Service. The Customer should not intentionally submit such data unless necessary for its use of the Service and lawful to do so.
Categories of Data SubjectsWhere Personal Data is incidentally contained in Customer Data, Data Subjects may include employees, contractors, supplier personnel or other individuals referred to in the Customer’s documentation or records.
Documented instructionsThe Customer instructs Progressio.ai to process Personal Data as necessary to provide the Service in accordance with the Terms, applicable Order Form, this DPA, Customer configuration and use of the Service, and additional documented instructions agreed between the parties.
Controller obligationsThe Customer determines the purposes for which Customer Data is made available to the Service and remains responsible for the lawfulness of that processing, including establishing any required lawful basis and providing required privacy information.

Schedule 2: Technical and Organisational Measures

Progressio.ai maintains technical and organisational measures designed to protect Personal Data processed in connection with the Service. Current measures include:

1. Hosting and infrastructure

The Service is hosted using Google Cloud infrastructure in Europe. Specific hosting regions may vary according to the relevant deployment and configuration.

2. Encryption

Data processed through the Service is protected using AES-256 encryption at rest and TLS 1.3 encryption in transit.

3. Production access

Access to the production environment is restricted to three members of Progressio.ai’s technical team.

4. Authentication

Access to Google Cloud administration requires authenticated user credentials.

Access to Customer accounts within the Service requires authenticated user credentials.

5. Customer Data retention

Underlying Customer Data is not retained as part of the normal operation of the Service after the relevant processing is complete. Customer Data used for an assessment is automatically deleted following processing, except where retention is required by law or expressly requested or agreed by the Customer in accordance with the Terms.

Audit Results may be retained in accordance with the Terms.

Where a Customer expressly requests that specified excerpts or other source material be retained, those materials remain Customer Data and are protected accordingly.

6. Access limitation

Progressio.ai limits access to production systems and Customer Data to personnel authorised to access those systems for the development, operation, support or security of the Service.

7. Review and development of controls

Progressio.ai may update its technical and organisational measures as the Service and its security arrangements develop, provided that the overall level of protection afforded to Personal Data is not materially reduced.

Schedule 3: Sub-processors

Progressio.ai maintains a current list of Sub-processors authorised under Section 9.

The current list, including the purpose of processing and relevant processing location where applicable, will be made available to the Customer on request.

Progressio.ai will notify Customers of intended additions or replacements of Sub-processors that process Personal Data in accordance with Section 9 of this DPA.