This agreement forms part of the terms for requesters where 50heads processes personal data on your behalf, for example personal data in questions, context or images you upload. It applies automatically to Team accounts and to any requester who asks for it. It meets Article 28 of the UK GDPR and EU GDPR.

1. Roles

You are the controller of personal data you include in questions ("customer data"). 50heads Ltd is your processor for it. For heads' data and our own account data, 50heads is an independent controller under our privacy notice.

2. Instructions

We process customer data only to provide 50heads as described in the terms, and on your documented instructions, which these terms and your use of the service make up. We'll tell you if we think an instruction breaks data protection law.

3. Confidentiality

Everyone at 50heads who can access customer data is bound by confidentiality.

4. Security

We keep appropriate technical and organisational measures, including: encryption in transit and at rest; access limited by role, with multi-factor authentication and audit logs; separation of production data; regular backups; vulnerability management and annual penetration testing; and a documented incident response procedure.

5. Subprocessors

You authorise the subprocessors on our subprocessors page. We impose data protection terms on each that are at least as protective as these. We give at least 30 days' notice of a new subprocessor through the page's change notices; you can object on reasonable grounds, and if we can't resolve it you may end the affected service and receive a refund of unused credits.

6. International transfers

Where customer data leaves the UK or EU, we use a lawful transfer mechanism: an adequacy decision or the UK Extension to the EU–US Data Privacy Framework, or the UK International Data Transfer Agreement or EU Standard Contractual Clauses, which are incorporated by reference.

7. Helping you

We'll help you, taking into account the nature of the processing, to respond to data subjects exercising their rights, and with data protection impact assessments and consultations with regulators.

8. Breaches

We'll tell you without undue delay, and within 48 hours of becoming aware, of a personal data breach affecting customer data, with the information you need to meet your own obligations.

9. Deletion

When the service ends, we delete customer data within 30 days, unless the law requires us to keep it. Results you've exported are yours to manage.

10. Audits

We'll make available the information needed to show we meet this agreement, including summaries of our security testing. Where that isn't enough, you may audit us once a year on 30 days' notice, at your cost, during business hours, under confidentiality.

11. Liability and law

Liability under this agreement is subject to the limits in the terms. This agreement is governed by the law of England and Wales.

To request a signed copy, email legal@50heads.com.