Data Processing Addendum
Last updated: 30/06/2026
This Data Processing Addendum ("DPA") forms part of the agreement between you (the "Customer", "Controller", "you") and Elevate Market Intelligence Limited (company number 16329736, registered office 6 Lucky Lane, Exeter, EX2 4UJ — "Elevate", "Processor", "we", "us") for your use of our products and services that involve us processing personal data on your behalf, in particular our segmentation and customer-intelligence tools (the "Services"). It governs our processing of personal data that you provide or make accessible to us, or that we process on your instructions, in connection with the Services ("Customer Personal Data"). Where this DPA conflicts with the rest of our terms on data protection, this DPA prevails.
In this DPA, "Data Protection Laws" means the UK GDPR, the Data Protection Act 2018, PECR, and all other data protection and privacy laws applicable to the processing. Terms such as "controller", "processor", "data subject", "personal data", "processing" and "personal data breach" have the meanings given in the UK GDPR.
1. Roles of the parties
1.1 As between the parties, you are the controller and we are the processor of the Customer Personal Data, except where you act as a processor for a third party, in which case we are a sub-processor and you ensure your own controller's instructions allow this arrangement.
1.2 You are responsible for the lawfulness of the Customer Personal Data and of your instructions, including establishing a lawful basis, providing required privacy information to data subjects, and obtaining any necessary consents. We process Customer Personal Data only as a processor on your behalf.
2. Our obligations as processor
We will:
(a) process Customer Personal Data only on your documented instructions, including as set out in this DPA and the Services' configuration, unless we are required to process by law (in which case we will, where lawful, inform you first);
(b) ensure that personnel authorised to process Customer Personal Data are bound by appropriate confidentiality obligations;
(c) implement and maintain appropriate technical and organisational measures to protect Customer Personal Data, as described in section 5;
(d) tell you without undue delay if, in our opinion, an instruction infringes Data Protection Laws;
(e) taking into account the nature of the processing and the information available to us, assist you (at your cost where the assistance is substantial) in responding to data-subject requests and in complying with your obligations on security, breach notification, data protection impact assessments and prior consultation with the regulator; and
(f) make available to you information reasonably necessary to demonstrate our compliance with this DPA.
3. Details of the processing
Subject matter and duration: processing of Customer Personal Data for the term of your use of the Services and as otherwise set out in this DPA.
Nature and purpose: hosting, storing, organising, analysing, segmenting, enriching and otherwise processing the data to provide the Services to you (for example creating customer segments and insights, and returning outputs to you and, where you direct, to platforms you connect).
Types of personal data: as determined by the data you connect or provide. This typically includes contact identifiers (often an email address, which we hash to an MD5 value before storage), and order, transaction and address-level data. We do not treat address data or order data as identifying a living individual on its own, but we handle the connected dataset as Customer Personal Data. You must not provide special-category personal data unless we have agreed this in writing.
Categories of data subjects: your customers, prospects and contacts, as determined by the data you connect or provide.
4. Sub-processors
4.1 You give us general authorisation to engage sub-processors to help provide the Services. We impose data-protection obligations on each sub-processor that are no less protective than those in this DPA, and we remain responsible to you for their performance.
4.2 We use sub-processors such as cloud hosting and infrastructure providers, our payment processor (Stripe), product and web analytics providers, transactional and marketing email providers, and AI/large-language-model providers used to generate insights. A current list of sub-processors is available on request.
4.3 We will give you reasonable notice of any intended addition or replacement of a sub-processor and a means to object on reasonable data-protection grounds. If you reasonably object, we will work with you in good faith to find a solution, and if we cannot, you may stop using the affected part of the Services.
5. Security
5.1 We maintain appropriate technical and organisational measures to protect Customer Personal Data against accidental or unlawful destruction, loss, alteration, unauthorised disclosure or access. These include encryption of data in transit and at rest, field-level encryption of sensitive fields, hashing of email identifiers (MD5) before storage, access controls on a need-to-know basis, network and infrastructure security, and logging and monitoring.
5.2 We do not store or sell payment card details (these are handled by Stripe), and our segmentation processing is designed to minimise the personal data we retain.
6. Personal data breaches
We will notify you without undue delay after becoming aware of a personal data breach affecting Customer Personal Data, and will provide information reasonably available to us to help you meet your own notification obligations.
7. International transfers
7.1 We host and process Customer Personal Data in the United Kingdom and/or the European Economic Area (EEA). Where any transfer of Customer Personal Data takes place to a country not subject to a UK adequacy decision (for example where a sub-processor processes data outside the UK/EEA), we put in place an appropriate transfer mechanism, such as the UK International Data Transfer Agreement or the UK Addendum to the EU Standard Contractual Clauses, together with any additional safeguards required.
7.2 Where AI/large-language-model providers are used to generate insights, we use providers and configurations intended to keep processing within appropriate safeguards, and we do not authorise them to use Customer Personal Data to train their models other than as needed to provide the service to us.
8. Audits
We will, on reasonable prior written notice and no more than once a year (unless required by a regulator or following a breach), allow you or your appointed auditor to verify our compliance with this DPA, subject to confidentiality and to not unreasonably disrupting our operations. We may satisfy audit requests by providing relevant documentation and responding to a reasonable security questionnaire.
9. Return and deletion
On termination of the Services, or on your written request, we will delete or return Customer Personal Data and delete existing copies within a reasonable period (and in any event within 30 days), unless the law requires us to retain it. Aggregated or anonymised data that no longer identifies any individual is not subject to this obligation.
10. Liability
Each party's liability under this DPA is subject to the limitations and exclusions of liability in the main agreement or applicable product terms between you and us. Nothing in this DPA limits any liability that cannot be limited under Data Protection Laws.
11. General
11.1 This DPA takes effect alongside your use of the Services and continues for as long as we process Customer Personal Data on your behalf.
11.2 This DPA is governed by the law of England and Wales and is subject to the exclusive jurisdiction of the courts of England and Wales.
11.3 If you require a countersigned copy of this DPA, or a copy adapted for your own controller arrangements, contact us at [email protected].
Contact: [email protected] · +44 (0)1392 542 833 · Elevate Market Intelligence Limited, 6 Lucky Lane, Exeter, EX2 4UJ · ICO registration ZB970398