REVIEW-READY DRAFT — GBOS-specific and factual, but NOT final and NOT legal advice. Must be confirmed by a qualified solicitor before GBOS relies on it (see the [SOLICITOR TO CONFIRM] items).

Data Processing Addendum (DPA)

Version 2026-08-r1 · Effective 2026-08-02

Terms for GBOS processing personal data on your behalf (UK GDPR Art. 28).

1. Roles and instructions

For Customer Data, the Customer is the controller and GBOS is the processor. GBOS processes personal data only on the Customer’s documented instructions — being the provision of the Service, these Terms, and any further written instruction the Customer gives — and will inform the Customer if an instruction infringes applicable data-protection law.

2. Subject matter, duration, nature and purpose

Subject matter: provision of the GBOS platform (the “Service”). Duration: the subscription term plus any retention/export window. Nature and purpose: hosting and processing the business records the Customer inputs (finance, contacts, documents and related records) to deliver the Service. Categories of data subjects and personal data: the Customer’s personnel, customers and counterparties as reflected in Customer Data. A DPIA template is provided to help the Customer assess high-risk processing.

3. Confidentiality and security (Art. 32)

GBOS ensures persons authorised to process personal data are bound by confidentiality, and implements the technical and organisational measures set out in the Security Schedule (Annex II), including database-enforced tenant isolation (row-level security, fail-closed), an HMAC-keyed append-only audit trail, MFA and server-verified step-up, encryption in transit, and rate limiting.

Encryption at rest is provided by the hosting/database providers; an application-level secret vault (AES-256-GCM envelope encryption) exists as a seam, with the external KMS integration pending owner activation. [SOLICITOR TO CONFIRM] that Annex II adequately describes the measures for Art. 32.

4. Sub-processors

The Customer authorises GBOS to engage the sub-processors listed on the Sub-processors page under written terms no less protective than this DPA. GBOS will maintain that list and notify of changes, allowing the Customer a reasonable period to object on reasonable data-protection grounds. [SOLICITOR TO CONFIRM] whether authorisation is general or specific and the length of the objection window.

5. Assistance, breach notification and records

Taking into account the nature of processing and the information available, GBOS assists the Customer to respond to data-subject requests and to meet its Art. 32–36 obligations, and notifies the Customer without undue delay after becoming aware of a personal-data breach affecting Customer Data. [SOLICITOR TO CONFIRM] the precise notification deadline and the assistance scope.

6. International transfers, return and deletion

Where processing involves a transfer of personal data outside the UK/EEA, the parties will put in place an appropriate transfer mechanism. [SOLICITOR TO CONFIRM] and attach the UK IDTA / EU SCCs and their Annexes.

On termination, GBOS deletes or returns Customer Data at the Customer’s choice using the in-product export and governed deletion, save where retention is legally required.

7. Audits

GBOS makes available information necessary to demonstrate compliance with this DPA and allows for and contributes to audits, on reasonable notice and subject to confidentiality, including through third-party reports where available.

Clauses a solicitor must confirm

The following points in this document require qualified legal sign-off before GBOS relies on it.

  • Standard Contractual Clauses / UK IDTA and their Annexes for international transfers (clause 6) — attach and complete.
  • Breach-notification timing commitment (clause 5) — set the concrete deadline (e.g. “without undue delay and within X hours”).
  • Sub-processor authorisation model (clause 4) — general vs specific authorisation and objection window.
  • Liability interaction with the main Terms (confirm the DPA does not inadvertently expand the liability cap).
  • Annex II security measures — confirm the Security Schedule is complete and current for Art. 32.

This document is a GBOS-specific, review-ready draft. It is not final and does not constitute legal advice; it must be confirmed by a qualified solicitor (see the clauses flagged above) before GBOS relies on it.