Highrise Digital Ltd

Data Processing Agreement

Last updated: 4 August 2026

This Data Processing Agreement (the “DPA”) forms part of the agreement under which Highrise Digital Ltd provides services to the Customer (the “Service Agreement”).

Highrise Digital Ltd is registered in England and Wales under company number 09989726. Its registered-office and other corporate details are available on the Company Information page.

In this DPA, Highrise Digital Ltd is referred to as the “Supplier” and the other party to the Service Agreement is referred to as the “Customer”.

This DPA applies where the Supplier processes Personal Data on the Customer’s behalf when providing the Services. This may include:

Definitions

In this DPA:

Agreement
means the Service Agreement, this DPA and any applicable order form, statement of work or service schedule.
Customer Personal Data
means Personal Data processed by the Supplier on behalf of the Customer under the Agreement.
Data Protection Laws
means all data protection and privacy laws applicable to the processing, including the UK GDPR, the Data Protection Act 2018 and the Privacy and Electronic Communications (EC Directive) Regulations 2003. It also includes the EU GDPR and other applicable national data protection laws where they apply to the processing. References to these laws include any amendments, replacements or re-enactments in force from time to time.
EU GDPR
means Regulation (EU) 2016/679.
Personal Data Breach
means a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of or access to Customer Personal Data.
Restricted Transfer
means a transfer of Personal Data that requires an adequacy decision, appropriate safeguard or other lawful transfer mechanism under applicable Data Protection Laws.
Services
means the services supplied under the Service Agreement.
Sub-processor
means another Processor appointed by the Supplier to process Customer Personal Data.
UK GDPR
means Regulation (EU) 2016/679 as it forms part of domestic law in the United Kingdom, as amended from time to time.

The terms “Controller”, “Processor”, “Data Subject”, “Personal Data”, “Processing” and “Supervisory Authority” have the meanings given to them in applicable Data Protection Laws. References to “including” or “includes” are illustrative and do not limit the words that precede them.

Roles and scope

For Customer Personal Data, the Customer is the Controller and the Supplier is the Processor, except where the Customer acts as a Processor for another Controller. In that case, the Supplier is the Customer’s Sub-processor.

Each party will comply with the obligations that apply to it under Data Protection Laws. The Supplier’s compliance with this DPA does not relieve the Customer of its own legal responsibilities.

The Customer is responsible for:

The Supplier may process information about the Customer’s personnel and representatives for its own legitimate business purposes, including account administration, billing, fraud prevention, security, legal compliance and the establishment or defence of legal claims. For that processing, the Supplier acts as an independent Controller and will process the information in accordance with the Highrise Digital Privacy Policy.

Processing instructions

The Supplier will process Customer Personal Data only:

The Agreement, together with the Customer’s authorised use and configuration of the Services, constitutes the Customer’s documented instructions.

If applicable law requires the Supplier to process Customer Personal Data other than on the Customer’s instructions, the Supplier will inform the Customer before carrying out that processing unless the law prohibits it from doing so.

If the Supplier reasonably believes that an instruction infringes Data Protection Laws, it will inform the Customer without undue delay. The Supplier may suspend the affected processing until the parties agree a lawful instruction.

The Supplier will not sell Customer Personal Data or use it for advertising or for purposes unrelated to providing, securing or supporting the Services.

Confidentiality

The Supplier will ensure that people authorised to process Customer Personal Data:

The Supplier will not disclose Customer Personal Data to a third party except as authorised by the Customer, permitted by the Agreement or required by law.

If the Supplier is legally required to disclose Customer Personal Data, it will inform the Customer before disclosure and provide a reasonable opportunity to challenge the requirement, unless the law prohibits this.

Security

The Supplier will implement and maintain appropriate technical and organisational measures designed to protect Customer Personal Data against accidental or unlawful destruction, loss, alteration, unauthorised disclosure or access.

When determining appropriate measures, the Supplier will take account of:

The Supplier’s current minimum security measures are described in Schedule 2. The Supplier may update those measures as technologies and risks change, provided that the overall protection of Customer Personal Data is not materially reduced.

Personal Data Breaches

The Supplier will notify the Customer without undue delay after becoming aware of a Personal Data Breach affecting Customer Personal Data.

To the extent the relevant information is available to the Supplier, its notification will include:

The Supplier may provide this information in phases as it becomes available and will take reasonable steps to investigate, contain and mitigate the breach.

The Customer is responsible for deciding whether notification to a Supervisory Authority or affected Data Subjects is legally required. At the Customer’s reasonable request, the Supplier will assist with those notifications, taking account of the nature of the processing and the information available to it.

Data Subject requests

If the Supplier receives a request from a Data Subject concerning Customer Personal Data, it will notify the Customer without undue delay and will not respond except:

Taking account of the nature of the processing, the Supplier will provide reasonable assistance to help the Customer respond to requests concerning Data Subject rights, including access, rectification, erasure, restriction, objection and data portability.

Compliance assistance

Taking account of the nature of the processing and the information available to it, the Supplier will provide reasonable assistance to help the Customer comply with its obligations concerning:

The Supplier may charge reasonable fees for assistance that is unusually extensive or falls outside the ordinary provision of the Services. The Supplier will not charge for assistance required as a direct result of its breach of this DPA.

Sub-processors

The Customer gives the Supplier general written authorisation to appoint Sub-processors in accordance with this section.

The Supplier may appoint a Sub-processor only where:

The Supplier will maintain an internal record of its current Sub-processors and will provide that information to the Customer on reasonable request.

The Supplier will give the Customer at least 14 days’ written notice before appointing a new Sub-processor or replacing an existing Sub-processor that will process Customer Personal Data. The notice will identify the Sub-processor, the service it provides and, where relevant, its processing location.

The Customer may object during the notice period where it has reasonable grounds relating to the protection of Customer Personal Data. The parties will work in good faith to resolve the objection. If the objection cannot reasonably be resolved, the Supplier may offer an alternative that avoids the relevant Sub-processor or allow the Customer to terminate the affected part of the Services.

Where urgent action is reasonably necessary to maintain security or service continuity, the Supplier may appoint or replace a Sub-processor on shorter notice. It will inform the Customer as soon as reasonably practicable.

The Supplier remains responsible to the Customer for the performance of its Sub-processors’ data protection obligations.

International transfers

The Supplier will not make a Restricted Transfer of Customer Personal Data unless:

Where required, the Supplier will undertake or assist with a transfer risk assessment or other applicable data protection test and implement reasonable supplementary measures.

The Customer authorises transfers to the locations identified in the Agreement or in information about the Supplier’s Sub-processors provided to the Customer, subject to the safeguards in this section.

Each party will reasonably cooperate in entering into any additional transfer documentation required by Data Protection Laws.

Return and deletion

On termination or expiry of the Services, the Supplier will, at the Customer’s choice, return or delete Customer Personal Data unless applicable law requires its continued retention.

Unless the Agreement states otherwise:

If deletion from a particular system is not immediately technically practicable, the Supplier will isolate the relevant Customer Personal Data from further use and delete it during the next applicable deletion or backup cycle.

Compliance information and audits

The Supplier will make available information reasonably necessary to demonstrate its compliance with this DPA and Article 28 of the applicable GDPR.

Where reasonably sufficient, the Supplier may meet this obligation initially by providing:

If that information is not reasonably sufficient, the Customer may conduct an audit itself or through an independent auditor. Unless a Personal Data Breach, reasonable evidence of non-compliance or a requirement from a Supervisory Authority justifies otherwise:

The Supplier will inform the Customer without undue delay if, in its reasonable opinion, an audit instruction would infringe Data Protection Laws or compromise the rights of another customer or Data Subject.

Term and precedence

This DPA takes effect when the Service Agreement begins and continues for as long as the Supplier processes Customer Personal Data.

If there is a conflict concerning the processing of Customer Personal Data, the following order of precedence applies:

  1. any mandatory Standard Contractual Clauses, UK Addendum or International Data Transfer Agreement;
  2. this DPA;
  3. the Service Agreement; and
  4. any other document forming part of the Agreement.

The limitations and exclusions of liability in the Service Agreement apply to this DPA to the fullest extent permitted by law.

Schedule 1: Processing details

Subject matter

Personal Data stored in, submitted to, transmitted through or otherwise processed using the Services, together with Personal Data accessed by the Supplier when providing support, maintenance, development, migration or other agreed services.

Duration

For the term of the Services and the return, retention and deletion periods described in the Agreement.

Nature of the processing

The processing may include:

Purposes

To provide, maintain, secure and support the contracted Services in accordance with the Customer’s documented instructions. This may include:

Categories of Data Subject

Depending on the Services and the Customer’s use of them, Data Subjects may include:

Categories of Personal Data

Depending on the Services and the Customer’s use of them, Customer Personal Data may include:

Special-category and criminal-offence data

The Services are not intended to require special-category or criminal-offence data unless this is inherent in the agreed Services or expressly agreed with the Customer.

If the Customer submits such data, it is responsible for ensuring that it has an appropriate lawful basis and condition for processing it. The Customer must inform the Supplier where additional measures are reasonably required because of the sensitive nature or scale of the processing.

Customer’s rights

The Customer may:

Schedule 2: Security measures

The Supplier will apply measures appropriate to the relevant Services and risks, including the following where applicable:

Access and authentication

Encryption and devices

System and software security

Development and testing

Backup and resilience

Organisational measures